CVE-2026-44278

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert att

Severity
Low 2.1
CVSS 3.1
Exploited
Not listed
EPSS
0.001
0.8th percentile
Discovered by
Third party
Vendor advisory field
Published
May 12, 2026
Assigned by fortinet

Description

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

Weakness: CWE-321

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientWindows

Credit

Fortinet is pleased to thank Alex Ghiotto of HackerHood Research Group for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiClientWindows version 7.4.3 or above

Something wrong here?