CVE-2025-62676Disclosure(fortinet / forticlient)

MEDIUMCVSS 7.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet forticlient systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forticlient

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
forticlient

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-15: 1Mentions · 2026-02-20: 2Mentions · 2026-06-06: 1Active Exploitation · 2026-06-06: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-06-06: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-20: 2Technical Details · 2026-06-06: 102-1502-2006-06
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
Active Exploitation
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-151
Disclosure1
2026-02-202
Disclosure1Patch1
2026-06-061
Active Exploitation1
Full discourse4 posts
  • transilienceai@transilienceai
    Disclosure

    @Sh4hdov CVE-2025-62676 is a confirmed local privilege escalation vulnerability in Fortinet FortiClient Windows. It allows low-privileged attackers to overwrite arbitrary files and execute code as SYSTEM via a junction in the FortiClient Configuration Daemon. #CVE2025 #Fortinet

    Post summary

    The tweet announces CVE‑2025‑62676 as a confirmed local privilege escalation flaw in FortiClient Windows, enabling attackers to overwrite files and run code as SYSTEM via a junction, with no PoC, exploit, patch, or active exploitation details provided.

    1000056
    311 followersView on X
  • Shahdov@Sh4hdov
    Patch

    CVE-2025-62676 allows local privilege escalation prior to the latest update. If you’re running FortiClient in your environment, make sure you’re patched. Stay safe out there. 🤙 #cybersecurity #informationtechnology https://t.co/5BUPJSVp1w

    Post summary

    FortiClient users are warned of a local privilege escalation flaw in CVE-2025-62676 and urged to apply the latest patch.

    1000072
    2 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2025-62676 An Improper Link Resolution Before File Access ('Link Follo… CVSS 7.1 | EPSS 0.00 (0th pctl) ⚡ Exploit in the wild ✅ Patch available Full analysis → https://sec.kaitan.id/cves/CVE-2025-62676 #Fortinet #CyberSecurity #InfoSec

    Post summary

    The post highlights that CVE-2025-62676 is being actively exploited in the wild and that a vendor patch is available to mitigate the risk.

    0000048
    82 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚡ CVE-2025-62676: Fortinet (CVSS: 6.4)... FortiClient's symlink vulnerability enables privilege escalation through named pipe manipulation - classic TOCTOU attac... https://zerodaysignal.com/vulnerability/CVE-2025-62676 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    FortiClient has a symlink TOCTOU vulnerability (CVE‑2025‑62676) that allows privilege escalation via named pipe manipulation; no PoC, exploit, or patch has been disclosed.

    00000106
    131 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetforticlient-windows-

Explore more