logo

A Vulnerability in Fortinet FortiClientEMS Could Allow for Arbitrary Code Execution

ID: a9d475df-cd65-5c61-b3da-47a57c0cd893

STIX ID: report--a9d475df-cd65-5c61-b3da-47a57c0cd893

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2026-04-04

Date Updated: 2026-04-27

...
...

A vulnerability (CVE-2026-35616) in Fortinet FortiClientEMS versions 7.4.5–7.4.6 permits unauthenticated remote code execution via crafted network requests; successful exploitation could allow attackers to run code with the affected service account's privileges, potentially installing programs, modifying or deleting data, or creating new accounts. The report maps the issue to Initial Access (TA0001) and Exploitation of Public-Facing Application (T1190).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.