Junglewise Threat Intelligence

CVE-2026-35616: Fortinet FortiClientEMS improper access control in API

CVE-2026-35616 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-04-04

Technologies: Fortinet FortiClient EMS. Vendors: Fortinet.

Executive brief

FortiClient EMS is a management platform used by organizations to deploy and manage endpoint security software across their network. A critical security flaw in this system allows an unauthenticated attacker to remotely execute commands or malicious code. This could lead to a total compromise of the management server, potentially allowing the attacker to gain control over all connected employee devices or disrupt corporate security operations.

Technical details

An improper access control vulnerability (CWE-284) exists within the API component of Fortinet FortiClientEMS versions 7.4.5 and 7.4.6. The flaw allows a remote, unauthenticated attacker to bypass authorization checks and execute arbitrary code or system commands by sending specially crafted network requests to the management interface. This vulnerability has a CVSS score of 9.8 and has been confirmed by the vendor and CISA to be exploited in the wild. Fortinet has released hotfixes for the affected versions and recommends upgrading to version 7.4.7 or higher to permanently resolve the issue.

Affected products

  • Fortinet FortiClientEMS 7.4.5 through 7.4.6

Timeline

  • 2026-04-03: disclosed: Initial CVE record received from Fortinet
  • 2026-04-04: advisory: Fortinet published PSIRT advisory FG-IR-26-099
  • 2026-04-04: exploited: Fortinet confirmed exploitation in the wild in their advisory
  • 2026-04-06: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog

References

Related threats