logo

CISA orders feds to patch exploited Fortinet EMS flaw by Friday

ID: c4009cd3-b91f-5a60-9ee3-1c96cdb9a53d

STIX ID: report--c4009cd3-b91f-5a60-9ee3-1c96cdb9a53d

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

**Executive summary:** CISA ordered federal agencies to urgently patch FortiClient EMS after active exploitation of CVE-2026-35616, a pre-auth API access bypass that can allow unauthenticated attackers to execute commands; Fortinet released hotfixes and warned customers while Shadowserver reports nearly 2,000 exposed EMS instances worldwide.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.