Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
ID: c4a767a2-ca5c-5b9b-aab1-2a41fdfc3719
STIX ID: report--c4a767a2-ca5c-5b9b-aab1-2a41fdfc3719
Feed Name: The Hacker News
Threat Score
### Executive summary Fortinet issued an out-of-band hotfix for a critical pre-authentication API access bypass in FortiClient EMS (CVE-2026-35616, CVSS 9.1) that permits privilege escalation and remote code/command execution; the flaw affects versions 7.4.5–7.4.6 and has been observed exploited in the wild (exploitation attempts recorded from March 31, 2026), so customers are urged to apply the hotfix or upgrade to the patched release immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
