FortiClient EMS zero-day exploited in the wild (CVE-2026-35616)
Fortinet released emergency hotfixes for CVE-2026-35616, a critical (CVSS 9.8) improper access control flaw in FortiClient Endpoint Management Server that lets unauthenticated attackers bypass API authentication and run code, after exploitation was observed in the wild from 31 March 2026.
- Victim
- Fortinet FortiClient EMS customers
Over the Easter weekend of 4 April 2026, Fortinet released emergency hotfixes for CVE-2026-35616, a critical vulnerability in FortiClient Endpoint Management Server (EMS), the console organisations use to manage FortiClient software on their endpoints. Fortinet said it had observed the flaw "being actively exploited in the wild." The exploitation was spotted by the threat-intelligence firm Defused.
The bug is an improper access control issue that allows an API authentication and authorisation bypass. An unauthenticated attacker can send crafted requests to execute unauthorised code or commands. It carries a CVSS score of 9.8 and affects FortiClient EMS 7.4.5 and 7.4.6; the 7.2 branch is not affected. Fortinet said the hotfixes were sufficient to prevent exploitation, with a permanent fix planned for version 7.4.7.
Exploitation and exposure
Attackers first attempted exploitation on 31 March 2026, and activity intensified after the advisory was published. Shadowserver counted nearly 2,000 FortiClient EMS instances exposed to the internet, although it was unclear how many were vulnerable. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 6 April. watchTowr founder Benjamin Harris noted that attackers favour holiday weekends, when security teams have reduced capacity.
The zero-day followed CVE-2026-21643, a separate unauthenticated FortiClient EMS flaw disclosed in February 2026 that was also exploited in the wild, and it was unclear whether attackers were chaining or alternating the two bugs.
Why it matters
Endpoint management servers have privileged reach into every managed device, so a remote, unauthenticated compromise of FortiClient EMS can give attackers a launch point for deploying malware or ransomware across an organisation. Fortinet products are among the most frequently listed in CISA's KEV catalog, and repeated zero-days in the same product reinforce the need to keep management interfaces off the public internet.
Timeline
First exploitation attempts against FortiClient EMS are observed.
Fortinet publishes an advisory and emergency hotfixes for FortiClient EMS 7.4.5 and 7.4.6, confirming in-the-wild exploitation discovered by Defused.
CISA adds CVE-2026-35616 to its Known Exploited Vulnerabilities catalog.
Sources
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/
- cyberscoop.comhttps://cyberscoop.com/fortinet-forticlient-ems-zero-day-cve-2026-35616-hotfix-known-exploited/