API authentication and authorization bypass
CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6, by following the instructions at:https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484 - for FortiClientEMS 7.4.5https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484 - for FortiClientEMS 7.4.6Upcoming FortiClientEMS 7.4.7 will also include a fix for this issue. In the meantime the hotfix above is sufficient to prevent it entirely. Revised on 2026-04-04 00:00:00
CSIRTS triage
- What
- An improper access control vulnerability allows unauthenticated attackers to execute unauthorized code or commands.
- Who is affected
- Customers using FortiClient EMS versions 7.4.5 and 7.4.6 are affected.
- Urgency
- Remediation is urgent as the vulnerability is actively exploited in the wild.
- Action
- Install the hotfix for FortiClient EMS 7.4.5 and 7.4.6.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiClient EMS
Get an email when a new FortiClient EMS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-099
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-35616Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.8% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-35616 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploitedCVE-2026-35616: Fortinet FortiClient EMS Improper Access Control Vulnerabilitycisa-kev
More from Fortinet FortiGuard PSIRT
- unknownServer-Side Request Forgery (SSRF)2026-08-12
- unknownContent-Encoding WAF Evasion2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownBroken access control in the RADIUS type admin group2026-08-12
- unknownUI DoS attack2026-08-12