FortiClient EMS Hotfixes Leave Uncertainty for 8.0 Users

Fortinet released emergency hotfixes for a critical zero-day vulnerability (CVE-2026-35616) in FortiClient EMS versions 7.4.5 and 7.4.6 after active exploitation was observed. The flaw allows unauthenticated attackers to bypass API authentication and execute unauthorized code or commands remotely. Fortinet plans a full patch in version 7.4.7, but has not clarified the status for version 8.0, leaving users on that branch exposed. This vulnerability follows a recent critical SQL injection flaw in the same product, indicating FortiClient EMS is a recurring target rather than a one-off risk.

Part of the PlainSec briefing for 2026-05-04

Sources