FortiClient EMS zero-day exploited in the wild (CVE-2026-35616)
Fortinet released emergency hotfixes for CVE-2026-35616, a critical (CVSS 9.8) improper access control flaw in FortiClient Endpoint Management Server that lets unauthenticated attackers bypass API authentication and run code, after exploitation was observed in the wild from 31 March 2026.
- Victim
- Fortinet FortiClient EMS customers