cbcvebase.
CVE-2026-35616
published 2026-04-04

CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2026-04-09
Exploited in the wild
EPSS
88.50%
99.8th percentile
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Affected

5 ranges
VendorProductVersion rangeFixed in
fortinetforticlientems
fortinetforticlientems
fortinetforticlientems
fortinetforticlientems7.4.5 – 7.4.6
fortinetfortinet

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://fortiguard.fortinet.com/psirt/FG-IR-26-099
  • CVE-2026-35616 affects Fortinet FortiClient EMS with a CVSS score of 9.1; exploitation involves crafted requests by unauthenticated attackers to execute unauthorized code or commands. Monitor FortiClient EMS for anomalous unauthenticated request patterns.
  • Post-exploitation activity includes credential harvesting from Chromium-based browsers and Firefox, exfiltrated via PowerShell. Hunt for PowerShell processes spawned from or associated with FortiClient EMS processes, and monitor for browser credential store access.
  • CVE-2026-35616 has been exploited in the wild as a zero-day with public exploit code available. Prioritize patching internet-facing Fortinet FortiClient EMS instances immediately.
  • Check all internet-accessible Fortinet FortiClient EMS products for signs of compromise per CISA KEV guidance; remediation was due 2026-04-09.
  • ·CISA KEV lists the affected product as 'Fortinet FortiClient EMS' broadly; apply mitigations per vendor instructions at the Fortinet PSIRT advisory (FG-IR-26-099) and follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
  • ·Fortinet advises assessing exposure specifically for all internet-accessible instances of the affected product, not just internal deployments.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.