logo

New Fortinet Flaw Allows Unauthorized Access to Enterprise Systems

ID: 17f26f74-b791-599a-9a47-ed7737938fe2

STIX ID: report--17f26f74-b791-599a-9a47-ed7737938fe2

Feed Name: TechRepublic Security

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

Fortinet disclosed a critical zero-day in FortiClient EMS (CVE-2026-35616, CVSS 9.1) that enables pre-authentication API access bypass and potential privilege escalation; active exploitation was observed prior to public disclosure, prompting Fortinet to release emergency hotfixes and guidance to restrict EMS exposure, monitor logs, and harden access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.