FortiClient EMS Hotfixes Leave Uncertainty for 8.0 Users
Fortinet released emergency hotfixes for a critical zero-day vulnerability (CVE-2026-35616) in FortiClient EMS versions 7.4.5 and 7.4.6 after active exploitation was observed. The flaw allows unauthenticated attackers to bypass API authentication and execute unauthorized code or commands remotely. Fortinet plans a full patch in version 7.4.7, but has not clarified the status for version 8.0, leaving users on that branch exposed. This vulnerability follows a recent critical SQL injection flaw in the same product, indicating FortiClient EMS is a recurring target rather than a one-off risk.
14 sources · Apr 12
Community Assessment
Threat researchers report CVE-2026-35616 and CVE-2026-21643 both under active exploitation, with roughly 2,000 FortiClient EMS instances fingerprinted globally; coverage suggests broader exposure than the advisory alone implies.
CVSS 9.8 CRITICAL: a improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated… EPSS 91% (100th percentile).
Investigating FortiGate CVE-2025-59718 Exploitation: IR Tales from The Field
Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. This blog details exploitation insights, attack progression, and practical detection opportunities for defenders handling their own environments.