CVE-2026-59836

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information di

Severity
Medium 6.7
CVSS 3.1
Exploited
Not listed
EPSS
0.002
12.9th percentile
Discovered by
Third party
Vendor advisory field
Published
Jul 14, 2026
Assigned by fortinet

Description

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientEMS

Credit

Fortinet is pleased to thank Ramn Costales de Ledesma from Telefonica de Espaa for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.6 or above

Something wrong here?