logo

Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited

ID: 373b2398-95b2-518d-9108-aa7213e637f7

STIX ID: report--373b2398-95b2-518d-9108-aa7213e637f7

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

...
...

Fortinet has released emergency patches after two critical FortiClient EMS vulnerabilities (CVE-2026-35616, CVSS 9.1; and CVE-2026-21643, CVSS 9.8) were observed exploited in the wild. The flaws allow unauthenticated attackers to bypass API authentication or perform SQL injection that can lead to remote code execution and the pushing of malicious updates to endpoints; Fortinet urges immediate installation of hotfixes or upgrades and lists IoCs such as HTTP 500 responses on /api/v1/init_consts and unusual PostgreSQL errors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.