logo

CISA Warns of Fortinet 0-Day Vulnerability Actively Exploited in Attacks

ID: 7783a744-7d88-5b3b-a651-1b6b5aefb5df

STIX ID: report--7783a744-7d88-5b3b-a651-1b6b5aefb5df

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-21

Author: Guru Baran

...
...

CISA added CVE-2026-35616 to its KEV catalog after active exploitation was observed of a critical pre-authentication API access bypass in Fortinet FortiClient EMS (affecting 7.4.5 and 7.4.6) that can lead to unauthenticated remote code execution; Fortinet issued an emergency advisory and hotfix, Shadowserver found more than 2,000 publicly accessible EMS instances with confirmed exploitation, and U.S. federal agencies were given a three-day remediation deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.