Skip to content
CVE-2026-70465

CVE-2026-70465

www.fortiguard.com • August 14, 2026

A buffer copy without checking size of input vulnerability [CWE-120] in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.

Disable application based filtering in FortiClient EMS VPN configuration:

FortiClient EMS > Remote Access Profile > VPN Tunnel > "Toggle" Application Based

Extracted Entities

Attack Types (1)

Platforms (1)