Hardcoded Encryption Key Used for VPN Saved Passwords
CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00
CSIRTS triage
- What
- A missing authorization vulnerability allows local attackers to decrypt VPN passwords.
- Who is affected
- Authenticated local users of FortiClient on Windows.
- Urgency
- Remediation is important as it could lead to sensitive information disclosure.
- Action
- Apply patches or restrict access to the affected functionality.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiClient
Get an email when a new FortiClient advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-129
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-442780.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-44278 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Hardcoded Encryption Key
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-74892: openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone…nvd · 2026-08-17
- mediumCVE-2026-57262: A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected produc…nvd · 2026-08-11
- criticalCVE-2026-54363: CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unaut…nvd · 2026-07-30
- criticalCVE-2021-32086: An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a h…nvd · 2026-07-27
- mediumCVE-2026-39031: Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static …nvd · 2026-06-26
- highCVE-2026-9220: Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts request…nvd · 2026-06-26
More from Fortinet FortiGuard PSIRT
- unknownServer-Side Request Forgery (SSRF)2026-08-12
- unknownContent-Encoding WAF Evasion2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownBroken access control in the RADIUS type admin group2026-08-12
- unknownUI DoS attack2026-08-12