CVE‑2026‑35616 — Patch Status (FortiClient EMS)

 


CVE‑2026‑35616 — Patch Status (FortiClient EMS)

Vulnerability summary

  • CVE‑ID: CVE‑2026‑35616
  • Severity: Critical (CVSS 9.1)
  • Type: Improper access control / pre‑authentication API access bypass
  • Impact: Unauthenticated remote code or command execution
  • Exploitation: Confirmed active exploitation in the wild
  • Discovered by: Defused (Simo Kohonen) and Nguyen Duc Anh
    [thehackernews.com], [bleepingcomputer.com], [tenable.com]

Affected and fixed versions

Vulnerable

  • FortiClient EMS 7.4.5
  • FortiClient EMS 7.4.6

Not affected


Available patches (as of April 7 2026)

Immediate remediation (recommended now)

Fortinet has released out‑of‑band hotfixes for the affected builds:

  • EMS 7.4.5 hotfix
    https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484
  • EMS 7.4.6 hotfix
    https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484

Fortinet confirms these hotfixes fully mitigate CVE‑2026‑35616 and should be applied immediately, especially if EMS is internet‑exposed. [bleepingcomputer.com], [infosecuri...gazine.com]


Permanent fix

  • FortiClient EMS 7.4.7
    • Will include the complete integrated fix
    • Not yet generally available at the time of reporting
    • Recommended upgrade path once released

Popular posts from this blog

WSUS CVE-2025-59287 Mitigation

Cloud Infrastructures are Having a Bad Week

CVE-2025-58034 Fortinet Warnings and Mitigation