2,000+ FortiClient EMS Instances Exposed Online Amid Active RCE Vulnerability Exploits in the Wild
ID: 804619b9-20c2-5e73-817b-742d5a2a3301
STIX ID: report--804619b9-20c2-5e73-817b-742d5a2a3301
Feed Name: cybersecurityNews.com
Shadowserver warns that approximately 2,000 FortiClient EMS instances are publicly exposed and that two unauthenticated RCE vulnerabilities — CVE-2026-35616 (new) and CVE-2026-21643 — are confirmed exploited in the wild; a compromised EMS could allow attackers to execute arbitrary code, manipulate endpoint configurations, harvest VPN credentials, and maintain persistent access. Organizations are advised to apply Fortinet patches immediately, restrict internet-facing EMS access, review logs for anomalous activity, monitor Shadowserver’s dashboard, and enable SIEM/EDR alerts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
