New FortiClient EMS flaw exploited in attacks, emergency patch released
ID: 38d3ae86-3ce6-5da8-a97a-158ae815029d
STIX ID: report--38d3ae86-3ce6-5da8-a97a-158ae815029d
Feed Name: Bleeping Computer
Threat Score
Fortinet disclosed a critical, actively exploited FortiClient EMS vulnerability (CVE-2026-35616) — a pre-authentication API access bypass enabling unauthenticated code/command execution — and released emergency hotfixes for affected 7.4.5/7.4.6 installations while preparing a 7.4.7 release; security researchers reported in-the-wild exploitation and over 2,000 exposed EMS instances online.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
