Fortinet Issues Emergency Patch for FortiClient Zero-Day
ID: 964671a3-c6f7-5cce-89d5-93af20d919f2
STIX ID: report--964671a3-c6f7-5cce-89d5-93af20d919f2
Feed Name: Dark Reading
Fortinet disclosed CVE-2026-35616, a critical pre-authentication API access bypass in FortiClient Endpoint Management Server (CVSS 9.1) that has been exploited in the wild. Fortinet released a hotfix for affected 7.4.5/7.4.6 installations and plans a full fix in 7.4.7; CISA added the flaw to its Known Exploited Vulnerabilities catalog and a public proof-of-concept appeared on GitHub, increasing the likelihood of broader exploitation—organizations should apply the hotfix or update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
