Skip to content
Zero-dayOngoing

FortiClient EMS zero-day exploited in the wild (CVE-2026-35616)

Fortinet released emergency hotfixes for CVE-2026-35616, a critical (CVSS 9.8) improper access control flaw in FortiClient Endpoint Management Server that lets unauthenticated attackers bypass API authentication and run code, after exploitation was observed in the wild from 31 March 2026.

Victim
Fortinet FortiClient EMS customers
CVECVE-2026-35616

Over the Easter weekend of 4 April 2026, Fortinet released emergency hotfixes for CVE-2026-35616, a critical vulnerability in FortiClient Endpoint Management Server (EMS), the console organisations use to manage FortiClient software on their endpoints. Fortinet said it had observed the flaw "being actively exploited in the wild." The exploitation was spotted by the threat-intelligence firm Defused.

The bug is an improper access control issue that allows an API authentication and authorisation bypass. An unauthenticated attacker can send crafted requests to execute unauthorised code or commands. It carries a CVSS score of 9.8 and affects FortiClient EMS 7.4.5 and 7.4.6; the 7.2 branch is not affected. Fortinet said the hotfixes were sufficient to prevent exploitation, with a permanent fix planned for version 7.4.7.

Exploitation and exposure

Attackers first attempted exploitation on 31 March 2026, and activity intensified after the advisory was published. Shadowserver counted nearly 2,000 FortiClient EMS instances exposed to the internet, although it was unclear how many were vulnerable. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 6 April. watchTowr founder Benjamin Harris noted that attackers favour holiday weekends, when security teams have reduced capacity.

The zero-day followed CVE-2026-21643, a separate unauthenticated FortiClient EMS flaw disclosed in February 2026 that was also exploited in the wild, and it was unclear whether attackers were chaining or alternating the two bugs.

Why it matters

Endpoint management servers have privileged reach into every managed device, so a remote, unauthenticated compromise of FortiClient EMS can give attackers a launch point for deploying malware or ransomware across an organisation. Fortinet products are among the most frequently listed in CISA's KEV catalog, and repeated zero-days in the same product reinforce the need to keep management interfaces off the public internet.

Timeline

  1. First exploitation attempts against FortiClient EMS are observed.

  2. Fortinet publishes an advisory and emergency hotfixes for FortiClient EMS 7.4.5 and 7.4.6, confirming in-the-wild exploitation discovered by Defused.

  3. CISA adds CVE-2026-35616 to its Known Exploited Vulnerabilities catalog.

Sources

  1. helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/
  2. cyberscoop.comhttps://cyberscoop.com/fortinet-forticlient-ems-zero-day-cve-2026-35616-hotfix-known-exploited/

Related incidents

Zero-dayOngoing

SonicWall warns of two SMA 1000 zero-days exploited in the wild (CVE-2026-15409, CVE-2026-15410)

SonicWall issued an urgent advisory after attackers were caught chaining two zero-day flaws in its SMA 1000 secure remote-access appliances โ€” an unauthenticated SSRF rated CVSS 10.0 and a post-authentication command-injection bug โ€” with Rapid7 having observed the pair exploited in tandem against internet-facing devices before any patch existed.

Victim
SonicWall SMA 1000