Vulnerabilities · 160 days ago

FortiClient EMS Hotfixes Leave Uncertainty for 8.0 Users

Fortinet released emergency hotfixes for a critical zero-day vulnerability (CVE-2026-35616) in FortiClient EMS versions 7.4.5 and 7.4.6 after active exploitation was observed. The flaw allows unauthenticated attackers to bypass API authentication and execute unauthorized code or commands remotely. Fortinet plans a full patch in version 7.4.7, but has not clarified the status for version 8.0, leaving users on that branch exposed. This vulnerability follows a recent critical SQL injection flaw in the same product, indicating FortiClient EMS is a recurring target rather than a one-off risk.

CVE-2026-35616

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated… EPSS 91% (100th percentile).

CISA federal remediation date Apr 9

Timeline

Sources

14 sources covering this story

Entities

Vendor digest: Fortinet

Part of the PlainSec briefing for 2026-05-04

Editions

Related stories