CVE-2026-35616: FortiClient EMS API Auth Bypass Enables Command Execution
ID: 1b7af972-1588-5c94-a9b5-48ebcc21fc14
STIX ID: report--1b7af972-1588-5c94-a9b5-48ebcc21fc14
Feed Name: SOCRadar Blog
Threat Score
Fortinet disclosed CVE-2026-35616, a critical (CVSS 9.1) pre-authentication API auth/authorization bypass in FortiClient EMS (affecting 7.4.5–7.4.6) that can allow unauthenticated execution of commands; vendor-observed in-the-wild exploitation and an out-of-band hotfix were issued—organizations should apply the hotfix, restrict internet access to EMS, and review logs/back to late March 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
