Vulnerabilità ed exploit · Exploit zero-day

FortiClient EMS Hotfixes Leave Uncertainty for 8.0 Users

Fortinet released emergency hotfixes for a critical zero-day vulnerability (CVE-2026-35616) in FortiClient EMS versions 7.4.5 and 7.4.6 after active exploitation was observed. The flaw allows unauthenticated attackers to bypass API authentication and execute unauthorized code or commands remotely. Fortinet plans a full patch in version 7.4.7, but has not clarified the status for version 8.0, leaving users on that branch exposed. This vulnerability follows a recent critical SQL injection flaw in the same product, indicating FortiClient EMS is a recurring target rather than a one-off risk.

14 fonti · 12 apr

Valutazione della community

Threat researchers report CVE-2026-35616 and CVE-2026-21643 both under active exploitation, with roughly 2,000 FortiClient EMS instances fingerprinted globally; coverage suggests broader exposure than the advisory alone implies.

CVE-2026-35616

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 9.8 CRITICAL: a improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated… EPSS 9% (95º percentile).

Data di correzione federale CISA 9 apr · data superata

Cronologia

Fonti

Riepilogo fornitore: Fortinet

Part of the PlainSec briefing for 2026-04-04

Every edition of this story: FortiClient EMS Hotfixes Leave Uncertainty for 8.0 Users

Altro da oggi