logo

Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild

ID: fa094ba4-2d44-52ae-9b33-37c07f30126c

STIX ID: report--fa094ba4-2d44-52ae-9b33-37c07f30126c

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-04

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Critical FortiClient EMS zero-day (CVE-2026-35616) being actively exploited:** Fortinet disclosed a critical unauthenticated API authentication/authorization bypass in FortiClient Endpoint Management Server (EMS) with CVSSv3 9.1 that allows remote attackers to execute arbitrary commands; active exploitation was observed, only EMS 7.4.5 and 7.4.6 are affected, and emergency hotfixes plus an upcoming 7.4.7 release are available — organizations are urged to apply hotfixes, monitor EMS API logs for anomalous unauthenticated requests, and restrict external access while patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.