• News/
  • https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-fortinet-flaw-exploited-in-attacks-by-friday/

CISA orders feds to patch exploited Fortinet EMS flaw by Friday

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 6, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to secure FortiClient Enterprise Management Server (EMS) instances against an actively exploited vulnerability by Friday. Tracked as CVE-2026-35616, this security flaw was discovered by cybersecurity firm Defused, which described it as a pre-authentication API access bypass that can allow attackers to bypass authentication and authorization controls entirely. Fortinet released emergency hotfixes over the weekend to address the vulnerability and said the security issue stems from an improper access control weakness that unauthenticated attackers can exploit to execute code or commands via specially crafted requests. The company also warned that threat actors had been exploiting it in zero-day attacks and warned IT administrators to secure their EMS instances as soon as possible by applying the hotfixes or upgrading to FortiClient EMS version 7.4.7 when it becomes available. "Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6," the company said. Internet security watchdog group Shadowserver currently tracks nearly 2,000 FortiClient EMS instances exposed online, with more than 1,400 IPs in the United States and in Europe. However, there are no details on how many have already been patched or have vulnerable configurations. ​​On Monday, CISA added CVE-2026-35616 to its Known Exploited Vulnerabilitie...

Read full article

Affected Software

2 affected components
Fortinet FortiClient Enterprise Management Server (EMS)=7.4.5
Fortinet FortiClient Enterprise Management Server (EMS)=7.4.6

Frequently Asked Questions

1

Which Fortinet systems are affected by CVE-2026-35616?

The vulnerability affects FortiClient Enterprise Management Server (EMS). Fortinet specifically urged customers using FortiClient EMS 7.4.5 and 7.4.6 to install the available hotfixes.

2

What can an attacker do by exploiting this flaw?

The flaw is a pre-authentication API access bypass caused by improper access control. An unauthenticated attacker can bypass authentication and authorization controls and execute code or commands through specially crafted requests.

3

Is exploitation of this vulnerability confirmed?

Yes. Fortinet said it has observed the vulnerability being exploited in the wild, including in zero-day attacks, and CISA described it as actively exploited.

4

What remediation does the article recommend?

Administrators should secure affected EMS instances as soon as possible by applying Fortinet's emergency hotfixes. They can also upgrade to FortiClient EMS version 7.4.7 when it becomes available.

5

What deadline did CISA set for federal agencies?

CISA ordered federal agencies to secure affected FortiClient EMS instances by Friday.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203