2,000+ FortiClient EMS Instances Exposed Online as Attackers Exploit Active RCE Flaw
ID: 4e55d6af-52db-5d95-bc1a-b0ccf2e26116
STIX ID: report--4e55d6af-52db-5d95-bc1a-b0ccf2e26116
Feed Name: GBHackers
Threat Score
**Urgent:** Two critical unauthenticated RCE vulnerabilities (CVE-2026-35616, CVE-2026-21643) in Fortinet FortiClient EMS are being actively exploited in the wild; ~2,000 publicly exposed EMS servers worldwide could allow attackers to execute arbitrary commands, gain full system control, and deploy malware or ransomware — organizations must apply Fortinet patches and restrict EMS access immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
