Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityidentity-authentication-vulnerability

Fortinet Patches Multiple Vulnerabilities Across FortiClient and Other Products

Updated 3mo agoFirst seen Mar 11, 20262 sources

Fortinet released security updates addressing 22 vulnerabilities across multiple products, including FortiWeb, FortiSwitchAX, FortiManager, and FortiClient (Linux). The issues span multiple bug classes (e.g., authentication bypass, heap-based buffer overflow, and cleartext storage of sensitive information) and could enable outcomes such as security bypass, data tampering, denial-of-service, privilege escalation, information disclosure, and in some cases unauthorized code/command execution. Belgium’s CCB urged organizations to patch promptly and noted Fortinet reported no evidence of active exploitation at the time of the advisory.

One of the patched flaws, CVE-2026-24018 (CVSS 7.8), was detailed by the Zero Day Initiative (ZDI-26-186) as a local privilege escalation vulnerability in FortiClient. ZDI reported the flaw stems from handling of certain shared objects: a local attacker with the ability to run low-privileged code can create a symbolic link to coerce a service into loading an arbitrary shared object, enabling execution of attacker-controlled code as root. Fortinet issued a fix and published vendor guidance under FG-IR-26-083.

Share:
Fortinet Patches Multiple Vulnerabilities Across FortiClient and Other Products
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 11, 20264mo ago

Belgium CCB urges immediate patching of Fortinet vulnerabilities

Belgium's Centre for Cybersecurity Belgium published a warning that Fortinet had patched 22 vulnerabilities across multiple products and advised organizations to patch immediately. The notice reinforced the urgency of applying Fortinet's available security updates.

Mar 10, 20264mo ago

ZDI publicly discloses FortiClient vulnerability ZDI-26-186

The Zero Day Initiative publicly released details of CVE-2026-24018 as ZDI-26-186 under coordinated disclosure. The advisory described the improper handling of shared objects in FortiClient and rated the issue CVSS 7.8.

Fortinet releases fixes for CVE-2026-24018 in FortiClient

Fortinet issued an update to remediate the FortiClient local privilege escalation vulnerability and published details in FortiGuard PSIRT advisory FG-IR-26-083. A later Belgian CCB advisory also warned that Fortinet had patched 22 vulnerabilities across multiple products, including this issue.

Oct 29, 20258mo ago

Astra Security reports FortiClient privilege escalation flaw to Fortinet

Febin Mon Saji of Astra Security reported a local privilege escalation vulnerability in Fortinet FortiClient, later assigned CVE-2026-24018 and tracked by ZDI as ZDI-CAN-27581. The flaw could let a low-privileged local attacker use a symbolic link to have a service load a malicious shared object and execute code as root.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Fortinet Patches Multiple Vulnerabilities Across FortiClient and Other Products | Mallory