logo

Fortinet Issues Emergency Patch for FortiClient Zero-Day

ID: 964671a3-c6f7-5cce-89d5-93af20d919f2

STIX ID: report--964671a3-c6f7-5cce-89d5-93af20d919f2

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Rob Wright

...
...

Fortinet disclosed CVE-2026-35616, a critical pre-authentication API access bypass in FortiClient Endpoint Management Server (CVSS 9.1) that has been exploited in the wild. Fortinet released a hotfix for affected 7.4.5/7.4.6 installations and plans a full fix in 7.4.7; CISA added the flaw to its Known Exploited Vulnerabilities catalog and a public proof-of-concept appeared on GitHub, increasing the likelihood of broader exploitation—organizations should apply the hotfix or update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.