CVE-2026-35616
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated… EPSS 91% (100th percentile).
CISA federal remediation date Apr 9
Vulnerabilities · 160 days ago
Fortinet released emergency hotfixes for a critical zero-day vulnerability (CVE-2026-35616) in FortiClient EMS versions 7.4.5 and 7.4.6 after active exploitation was observed. The flaw allows unauthenticated attackers to bypass API authentication and execute unauthorized code or commands remotely. Fortinet plans a full patch in version 7.4.7, but has not clarified the status for version 8.0, leaving users on that branch exposed. This vulnerability follows a recent critical SQL injection flaw in the same product, indicating FortiClient EMS is a recurring target rather than a one-off risk.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated… EPSS 91% (100th percentile).
CISA federal remediation date Apr 9
14 sources covering this story
Investigating FortiGate CVE-2025-59718 Exploitation: IR Tales from The Field
Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. This blog details exploitation insights, attack progression, and practical detection opportunities for defenders handling their own environments.
AL26-007 - Vulnerability impacting Fortinet FortiClientEMS - CVE-2026-35616
Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploit
Fortinet has updated its FortiClient EMS product after zero-day attacks surfaced
Fortinet customers confront actively exploited zero-day, with a full patch still pending
Two critical defects in FortiClient EMS have been exploited in the past couple weeks.
Fortinet Issues Emergency Patch for FortiClient Zero-Day
The authentication bypass flaw, tracked as CVE-2026-35616, is the latest in a series of Fortinet vulnerabilities that have been exploited in the wild.
Attackers exploited the FortiClient EMS bug as a 0-day
: CISA added the flaw to KEV after Fortinet confirmed exploitation in the wild
The Record from Recorded Future
Singapore, US warn of latest Fortinet bug being exploited in wild
The Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Thursday to apply the hotfix.
CISA orders feds to patch exploited Fortinet EMS flaw by Friday
Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to secure FortiClient Enterprise Management Server (EMS) instances against an actively exploited vulnerability by Friday.
CVE-2026-35616 Fortinet FortiClientEMS zero-day exploited
CVE-2026-35616 Fortinet FortiClientEMS zero-day exploited in the wild
Critical flaw in FortiClient EMS under exploitation
Fortinet released an emergency hotfix after security researchers discovered the vulnerability being exploited as a zero-day.
Fortinet Rushes Emergency Fixes for Exploited Zero-Day
The improper access control bug in FortiClient EMS allows unauthenticated attackers to execute arbitrary code remotely.
Fortinet Rushes Emergency Fixes for Exploited Zero-Day
The improper access control bug in FortiClient EMS allows unauthenticated attackers to execute arbitrary code remotely.
Part of the PlainSec briefing for 2026-05-04