CVE-2026-24018Disclosure(fortinet / forticlient)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for fortinet forticlient systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forticlient

Threat summary

  • Public PoC and exploit tooling are both present
  • 8 mentions across 6 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-26); latest day: 2
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
forticlient

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-18: 1Mentions · 2026-03-26: 2Mentions · 2026-04-01: 2PoC Mentioned / Linked · 2026-03-26: 1Exploit Tool / Code · 2026-03-26: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-14: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-01: 203-1203-1303-1403-1803-2604-01
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Exploit
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-131
General1
2026-03-141
Disclosure1
2026-03-181
Disclosure1
2026-03-262
Disclosure1Exploit1
2026-04-012
Disclosure2
Full discourse8 posts
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    CVE-2026–24018: A Logic flaw to Local Privilege Escalation 0day $$ https://febinj.medium.com/cve-2026-24018-a-logic-flaw-to-local-privilege-escalation-0day-ff3a3b5bba69?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    A brief announcement of CVE-2026-24018, a logic flaw enabling local privilege escalation, with a link to a Medium article for details.

    0201031.1K
    40.1K followersView on X
  • ‘BBWriteups’@bbwriteup
    Disclosure

    "CVE-2026–24018: A Logic flaw to Local Privilege Escalation 0day $$$" by Febin #BugBounty #Cybersecurity #Hacking #InfoSec https://febinj.medium.com/cve-2026-24018-a-logic-flaw-to-local-privilege-escalation-0day-ff3a3b5bba69

    Post summary

    The tweet announces a newly disclosed CVE‑2026‑24018, describing it as a logic flaw that allows local privilege escalation, without providing evidence of an exploit, active exploitation, or a patch.

    0001061
    563 followersView on X
  • dbugs@ptdbugs
    Exploit

    CVE: CVE-2026-24018 PT-Identifier: PT-2026-24244 Vendor: Fortinet Product: FortiClientLinux CVSS: 7.4 Credits: n/a Description: A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-24018 • https://fortiguard.fortinet.com/psirt/FG-IR-26-083 Exploit: https://github.com/febin0x10/Fortinet_FortiClient_Exploit_CVE-2026-24018 #dbugs_vuln

    Post summary

    The CVE-2026-24018 vulnerability is a local privilege escalation via symbolic links in FortiClientLinux; a functional exploit script is publicly available, but no active attacks or patch information are disclosed.

    00010133
    759 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Fortinet ❗ CVE-2026-24018 ❗ CVE-2026-24017 ❗ CVE-2026-22627 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-fortinet-8/ https://t.co/b7lKkphDE9

    Post summary

    Three Fortinet CVEs are announced with a link for further information, but no technical or exploit details are provided.

    00010125
    6.6K followersView on X
  • Triune Digital Security Corporate LLP@triunedigisec
    Disclosure

    FortiClient for Linux affected with local privilege escalation vulnerability tracked as CVE-2026-24018. #cve #privesc #vulnerability https://t.co/TDgL5pf8Jw

    Post summary

    The post announces that FortiClient for Linux is affected by a local privilege escalation vulnerability (CVE‑2026‑24018) without providing further technical or remediation details.

    0000060
    94 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24018 A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and u… https://www.cve.org/CVERecord?id=CVE-2026-24018

    Post summary

    Fortinet FortiClient Linux 7.2.2‑7.4.4 are vulnerable to a symbolic link following flaw (CVE‑2026‑24018). No PoC, exploit, or patch information is provided.

    00000211
    56.7K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Fortinet FortiClient Link Following Local Privilege Escalation Vulnerability (CVE-2026-24018) #CVE202624018 #CyberSecurity #Fortinet #LocalPrivilegeEscalation https://www.systemtek.co.uk/?p=48732 https://t.co/xaJvsi1Y3W

    Post summary

    The post announces a new local privilege escalation vulnerability in Fortinet FortiClient (CVE‑2026‑24018) and links to a detailed article, but provides no PoC, exploit code, patch, or indication of active exploitation.

    0000067
    1.8K followersView on X
  • Anonymous Tech@Anonymous_Tech7
    Disclosure

    Fortinet FortiClient installations are vulnerable to local privilege escalation. Attackers can exploit CVE-2026-24018, assigned a CVSS rating of 7.8, to escalate privileges after obtaining low-privileged code execution on target systems, such as those at 192.168.1.1.

    Post summary

    Fortinet FortiClient is vulnerable to CVE‑2026‑24018, a local privilege escalation flaw with a CVSS score of 7.8. No PoC, exploit, patch, or evidence of active exploitation is referenced.

    0000063
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetforticlient-linux-

Explore more