Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild
ID: 08cac740-a620-5652-bd29-7bc98392de7d
STIX ID: report--08cac740-a620-5652-bd29-7bc98392de7d
Feed Name: securityonline.info
Threat Score
Fortinet has confirmed CVE-2026-35616, a critical (CVSS 9.1) Improper Access Control flaw in FortiClient EMS 7.4.5–7.4.6 that allows unauthenticated attackers to send crafted API requests to execute unauthorized code; Fortinet reports active exploitation in the wild and has released hotfixes for the affected 7.4.5/7.4.6 builds and recommends installing the emergency patches immediately and planning an upgrade to 7.4.7.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
