logo

FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)

ID: e80064f6-9b26-53e1-8bc8-cda3f7dcfe11

STIX ID: report--e80064f6-9b26-53e1-8bc8-cda3f7dcfe11

Feed Name: Help Net Security

Threat Score
88/100

Date Published: 2026-04-04

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Defused Cyber and Fortinet report active exploitation of a critical FortiClient EMS zero-day vulnerability (CVE-2026-35616) that allows API authentication/authorization bypass and potential unauthenticated code execution. Fortinet confirmed exploitation in the wild and issued hotfixes for FortiClient EMS 7.4.5 and 7.4.6 (with 7.4.7 to include a fix); impact on the 8.0 branch and whether this is being chained with a separate SQL injection zero-day (CVE-2026-21643) remain unclear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.