Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild
ID: fa094ba4-2d44-52ae-9b33-37c07f30126c
STIX ID: report--fa094ba4-2d44-52ae-9b33-37c07f30126c
Feed Name: cybersecurityNews.com
**Critical FortiClient EMS zero-day (CVE-2026-35616) being actively exploited:** Fortinet disclosed a critical unauthenticated API authentication/authorization bypass in FortiClient Endpoint Management Server (EMS) with CVSSv3 9.1 that allows remote attackers to execute arbitrary commands; active exploitation was observed, only EMS 7.4.5 and 7.4.6 are affected, and emergency hotfixes plus an upcoming 7.4.7 release are available — organizations are urged to apply hotfixes, monitor EMS API logs for anomalous unauthenticated requests, and restrict external access while patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
