logo

CVE-2026-35616: FortiClient EMS API Auth Bypass Enables Command Execution

ID: 1b7af972-1588-5c94-a9b5-48ebcc21fc14

STIX ID: report--1b7af972-1588-5c94-a9b5-48ebcc21fc14

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Fortinet disclosed CVE-2026-35616, a critical (CVSS 9.1) pre-authentication API auth/authorization bypass in FortiClient EMS (affecting 7.4.5–7.4.6) that can allow unauthenticated execution of commands; vendor-observed in-the-wild exploitation and an out-of-band hotfix were issued—organizations should apply the hotfix, restrict internet access to EMS, and review logs/back to late March 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.