Fortinet
FortiClient
See the latest tracked release, confirm when it was published, and subscribe for update emails.
6.4.10
- Release date
- March 17, 2026
- Security status
- Current version appears affected by 3 high-severity CVEs.
Source
Vendor Release Information
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 6.4.10 | 2026-03-17 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-70465 | HIGH (7.3) | 2026-08-12 | Current versionnot affected | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets. Affected versions
|
| CVE-2024-47574 | HIGH (7.4) | 2024-11-13 | Current versionaffected | A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed named pipe messages. Affected versions
Show 1 more
|
| CVE-2024-36513 | HIGH (7.4) | 2024-11-12 | Current versionaffected | A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts. Affected versions
Show 1 more
|
| CVE-2023-45590 | CRITICAL (9.4) | 2024-04-09 | Current versionaffected | An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website Affected versions
Show 2 more
|