Cato recently identified security vulnerabilities (CVE-2026-10726 and CVE-2026-10739) that impact Cato Windows Clients with versions lower than 6.12.6. This CVE can allow attackers who have access to the Windows Client on the device to escalate their privileges. The Cato Windows Client version 6.12.6 (and higher) includes a security patch that fully remediates this vulnerability.
We strongly recommend that you ensure all Windows Clients are upgraded to at least Windows Client version v6.12.6 to protect against the vulnerability. You can download the latest Windows Client version from the Client Rollout page in the Cato Management Application (open the page).
What Changes Do I Need to Make?
Use the Access Overview Dashboard to identify users who have Windows Client versions lower than v6.12.6. Then make sure that they upgrade to at least Windows Client v6.12.6 to receive the most recent security patches and enhancements.
Go to the Access Methods section and filter for Cato Client on Windows for the Top Client Version.

We recommend that you use the Cato upgrade service to automatically upgrade Clients to the newest version.
What is the Impact on the Account?
If you don’t upgrade to Windows Client v6.12.6 or higher - those devices with older Client versions are vulnerable to malicious attacks that use CVE-2026-10726 and CVE-2026-10739.
Who Do I Talk to If I Have Questions?
Please use the Cato Ask AI agent in the CMA for questions related to the Access Overview Dashboard and upgrading Windows Clients.
Take me to the CMA AI Workspace.