Fortinet released a hotfix on April 4, 2026 for a critical unauthenticated remote code execution vulnerability (CVE-2026-35616) in FortiClient EMS, affecting versions 7.4.5–7.4.6. The flaw stems from improper access control in the API authentication layer. Active exploitation in the wild has been confirmed by Fortinet, with Defused having observed exploitation prior to official disclosure. No public proof-of-concept is available yet, but further targeting is expected. A separate FortiClient EMS vulnerability (CVE-2026-21643), originally disclosed in February, is also now confirmed exploited in the wild as of March 24. Organizations are strongly advised to apply the available hotfix immediately, with a full fix expected in FortiClient EMS 7.4.7.

2m read timeFrom arcticwolf.com
Post cover image
Table of contents
Recommendation

Sort: