logo

Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

ID: c4a767a2-ca5c-5b9b-aab1-2a41fdfc3719

STIX ID: report--c4a767a2-ca5c-5b9b-aab1-2a41fdfc3719

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-04-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

### Executive summary Fortinet issued an out-of-band hotfix for a critical pre-authentication API access bypass in FortiClient EMS (CVE-2026-35616, CVSS 9.1) that permits privilege escalation and remote code/command execution; the flaw affects versions 7.4.5–7.4.6 and has been observed exploited in the wild (exploitation attempts recorded from March 31, 2026), so customers are urged to apply the hotfix or upgrade to the patched release immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.