CVE‑2026‑35616 — Patch Status (FortiClient EMS)

 


CVE‑2026‑35616 — Patch Status (FortiClient EMS)

Vulnerability summary

  • CVE‑ID: CVE‑2026‑35616
  • Severity: Critical (CVSS 9.1)
  • Type: Improper access control / pre‑authentication API access bypass
  • Impact: Unauthenticated remote code or command execution
  • Exploitation: Confirmed active exploitation in the wild
  • Discovered by: Defused (Simo Kohonen) and Nguyen Duc Anh
    [thehackernews.com], [bleepingcomputer.com], [tenable.com]

Affected and fixed versions

Vulnerable

  • FortiClient EMS 7.4.5
  • FortiClient EMS 7.4.6

Not affected


Available patches (as of April 7 2026)

Immediate remediation (recommended now)

Fortinet has released out‑of‑band hotfixes for the affected builds:

  • EMS 7.4.5 hotfix
    https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484
  • EMS 7.4.6 hotfix
    https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484

Fortinet confirms these hotfixes fully mitigate CVE‑2026‑35616 and should be applied immediately, especially if EMS is internet‑exposed. [bleepingcomputer.com], [infosecuri...gazine.com]


Permanent fix

  • FortiClient EMS 7.4.7
    • Will include the complete integrated fix
    • Not yet generally available at the time of reporting
    • Recommended upgrade path once released

Comments

Popular posts from this blog

Entire List Leaked for Canvas Ransomware Attack

WSUS CVE-2025-59287 Mitigation

Cloud Infrastructures are Having a Bad Week

CVE-2025-58034 Fortinet Warnings and Mitigation

Broadcom is dismantling of VMware Cloud Service Providers (VCSPs)

FBI Seizes RAMP Cybercrime Forum

Instagram Data Leak Update

CodeRED emergency alert system is currently down across many regions!

SitusAMC Breached!

Notepad++ update service was compromised