logo

CVE-2026-35616: Fortinet fixes actively exploited high-severity flaw

ID: 1398882b-8d75-57fd-ba6b-6d827591e92f

STIX ID: report--1398882b-8d75-57fd-ba6b-6d827591e92f

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Fortinet released out-of-band patches addressing a critical FortiClient EMS vulnerability (CVE-2026-35616, CVSS 9.1) that is being actively exploited in the wild; the flaw is an improper access control issue enabling unauthenticated attackers to bypass API authentication and escalate privileges. Fortinet urges users of FortiClient EMS 7.4.5 and 7.4.6 to install the hotfixes immediately, with a permanent fix scheduled in 7.4.7.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.