CVE‑2026‑35616 — Patch Status (FortiClient EMS)
CVE‑2026‑35616 — Patch Status (FortiClient EMS)
Vulnerability summary
- CVE‑ID: CVE‑2026‑35616
- Severity: Critical (CVSS 9.1)
- Type: Improper access control / pre‑authentication API access bypass
- Impact: Unauthenticated remote code or command execution
- Exploitation: Confirmed active exploitation in the wild
- Discovered by: Defused (Simo Kohonen) and Nguyen Duc Anh
[thehackernews.com], [bleepingcomputer.com], [tenable.com]
Affected and fixed versions
Vulnerable
- FortiClient EMS 7.4.5
- FortiClient EMS 7.4.6
Not affected
- FortiClient EMS 7.2.x and earlier
[securityweek.com], [bleepingcomputer.com]
Available patches (as of April 7 2026)
Immediate remediation (recommended now)
Fortinet has released out‑of‑band hotfixes for the affected builds:
- EMS 7.4.5 hotfix
https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484 - EMS 7.4.6 hotfix
https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484
Fortinet confirms these hotfixes fully mitigate CVE‑2026‑35616 and should be applied immediately, especially if EMS is internet‑exposed. [bleepingcomputer.com], [infosecuri...gazine.com]
Permanent fix
- FortiClient EMS 7.4.7
- Will include the complete integrated fix
- Not yet generally available at the time of reporting
- Recommended upgrade path once released
.png)