FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)
ID: e80064f6-9b26-53e1-8bc8-cda3f7dcfe11
STIX ID: report--e80064f6-9b26-53e1-8bc8-cda3f7dcfe11
Feed Name: Help Net Security
Threat Score
Defused Cyber and Fortinet report active exploitation of a critical FortiClient EMS zero-day vulnerability (CVE-2026-35616) that allows API authentication/authorization bypass and potential unauthenticated code execution. Fortinet confirmed exploitation in the wild and issued hotfixes for FortiClient EMS 7.4.5 and 7.4.6 (with 7.4.7 to include a fix); impact on the 8.0 branch and whether this is being chained with a separate SQL injection zero-day (CVE-2026-21643) remain unclear.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
