Attackers exploited this critical FortiClient EMS bug as a 0-day
ID: 2609007a-9578-5de7-9124-54bb7d553448
STIX ID: report--2609007a-9578-5de7-9124-54bb7d553448
Feed Name: The Register (Security)
Fortinet issued an emergency hotfix for a critical FortiClient EMS unauthenticated remote code execution vulnerability (CVE-2026-35616, CVSS 9.1) after evidence of active exploitation since March 31; CISA added the flaw to its Known Exploited Vulnerabilities catalog and required federal agencies to patch. Researchers observed low-and-slow targeted exploitation that quickly became opportunistic, and the vendor reported ongoing remediation and customer notifications while noting a relatively small internet-exposed footprint (~100 instances).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
