logo

U.S. CISA adds a flaw in Fortinet FortiClient EMS to its Known Exploited Vulnerabilities catalog

ID: de4a53b5-1771-5cf7-a9b1-d2bc7a4ec6ae

STIX ID: report--de4a53b5-1771-5cf7-a9b1-d2bc7a4ec6ae

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added Fortinet FortiClient EMS vulnerability CVE-2026-35616 (CVSS 9.1) to its Known Exploited Vulnerabilities catalog after Fortinet confirmed active in-the-wild exploitation; the flaw is an improper access control issue allowing unauthenticated API requests to bypass authentication and escalate privileges. Fortinet released out-of-band hotfixes for EMS 7.4.5 and 7.4.6, plans a permanent fix in 7.4.7, and CISA ordered federal agencies to remediate by April 9, 2026; observers recommend patching and monitoring for indicators such as X-SSL-CLIENT-VERIFY:SUCCESS from unknown IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.