CRITICALVulnerability
Global
Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
Sunday, April 5, 2026 at 04:32 AM UTC·Source: The Hacker News
Updated: Monday, April 6, 2026 at 12:17 AM UTC
Executive Summary
Fortinet has released out-of-band patches for a critical security flaw impacting FortiClient EMS that it said has been exploited in the wild. The vulnerability, tracked as CVE-2026-35616 (CVSS score: 9.1), has been described as a pre-authentication API access bypass leading to privilege escalation. "An improper access control vulnerability [CWE-284] in FortiClient EMS may allow an
Analysis
Fortinet has released out-of-band patches for a critical security flaw impacting FortiClient EMS that it said has been exploited in the wild. The vulnerability, tracked as CVE-2026-35616 (CVSS score: 9.1), has been described as a pre-authentication API access bypass leading to privilege escalation. "An improper access control vulnerability [CWE-284] in FortiClient EMS may allow an