logo

Attackers exploited this critical FortiClient EMS bug as a 0-day

ID: 2609007a-9578-5de7-9124-54bb7d553448

STIX ID: report--2609007a-9578-5de7-9124-54bb7d553448

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-04-06

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Fortinet issued an emergency hotfix for a critical FortiClient EMS unauthenticated remote code execution vulnerability (CVE-2026-35616, CVSS 9.1) after evidence of active exploitation since March 31; CISA added the flaw to its Known Exploited Vulnerabilities catalog and required federal agencies to patch. Researchers observed low-and-slow targeted exploitation that quickly became opportunistic, and the vendor reported ongoing remediation and customer notifications while noting a relatively small internet-exposed footprint (~100 instances).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.