logo

CISA Alerts Defenders to Actively Exploited Fortinet Zero-Day Vulnerability

ID: 12a3f6ac-1ba6-5735-835a-e3165ba6e79b

STIX ID: report--12a3f6ac-1ba6-5735-835a-e3165ba6e79b

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Divya

...
...

**CISA urgent warning:** CISA added CVE-2026-35616 — a critical, unauthenticated access-control bypass in Fortinet FortiClient Enterprise Management Server (EMS) that enables remote code execution — to its Known Exploited Vulnerabilities catalog on April 6, 2026; active exploitation has been observed, and organizations (including FCEB agencies) must apply vendor mitigations or discontinue EMS by the April 9, 2026 remediation deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.