Fortinet released an emergency patch over the weekend for a critical FortiClient Enterprise Management Server (EMS) bug believed to be under attack since at least March 31. The flaw, tracked as CVE-2026-35616, is an improper access control vulnerability that allows unauthenticated attackers to execute unauthorized code or commands via crafted requests. It earned a critical 9.1 CVSS rating, and in addition to urging customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6, the firewall vendor also warned that it has "observed this to be exploited in the wild." This product allows companies to centrally manage and secure both remote and office computers, and this bug is the second critical FortiClient flaw to come under attack in the past few weeks. In late March, security researchers warned that CVE-2026-21643, which also leads to unauthenticated remote code execution, was being actively exploited in the wild. On Monday, the US Cybersecurity and Infrastructure Security Agency (CISA) added the FortiClient EMS bug to its Known Exploited Vulnerabilities (KEV) Catalog, and set a Thursday deadline for all federal agencies to apply the patch. The Register asked Fortinet for more details about who was abusing the security hole, and how many customers had been affected. While the security software company declined to answer our specific questions, a Fortinet spokesperson told The Register that "Our PSIRT response and remediation efforts remain ongoing," and "we are communic...
Attackers exploited this critical FortiClient EMS bug as a 0-day
The Register
·Jessica Lyons
·Published Apr 6, 2026
·Updated
Affected Software
1 affected component
Fortinet FortiClient Enterprise Management Server=7.4.5, =7.4.6
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in FortiClient EMS that is being actively exploited by attackers.
2
What specific vulnerability is addressed in the article?
The vulnerability is identified as CVE-2026-35616 and involves improper access control.
3
When was the vulnerability first believed to be under attack?
The vulnerability is believed to have been under attack since at least March 31.
4
What actions has Fortinet taken in response to the vulnerability?
Fortinet released an emergency patch over the weekend to address the critical bug in FortiClient EMS.
5
Which versions of FortiClient EMS are affected by this vulnerability?
The affected versions are 7.4.5 and 7.4.6 of FortiClient Enterprise Management Server.