logo

Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild

ID: 08cac740-a620-5652-bd29-7bc98392de7d

STIX ID: report--08cac740-a620-5652-bd29-7bc98392de7d

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-04

Date Updated: 2026-04-23

Author: Ddos

...
...

Fortinet has confirmed CVE-2026-35616, a critical (CVSS 9.1) Improper Access Control flaw in FortiClient EMS 7.4.5–7.4.6 that allows unauthenticated attackers to send crafted API requests to execute unauthorized code; Fortinet reports active exploitation in the wild and has released hotfixes for the affected 7.4.5/7.4.6 builds and recommends installing the emergency patches immediately and planning an upgrade to 7.4.7.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.