CRITICALVulnerability
Global

Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

Sunday, April 5, 2026 at 04:32 AM UTC·Source: The Hacker News

Updated: Monday, April 6, 2026 at 12:17 AM UTC

Executive Summary

Fortinet has released out-of-band patches for a critical security flaw impacting FortiClient EMS that it said has been exploited in the wild. The vulnerability, tracked as CVE-2026-35616 (CVSS score: 9.1), has been described as a pre-authentication API access bypass leading to privilege escalation. "An improper access control vulnerability [CWE-284] in FortiClient EMS may allow an

Analysis

Fortinet has released out-of-band patches for a critical security flaw impacting FortiClient EMS that it said has been exploited in the wild. The vulnerability, tracked as CVE-2026-35616 (CVSS score: 9.1), has been described as a pre-authentication API access bypass leading to privilege escalation. "An improper access control vulnerability [CWE-284] in FortiClient EMS may allow an

Indicators of Compromise (1)

CVE (1)
CVE-2026-35616
Source Attribution

Originally published by The Hacker News on Apr 5, 2026.

Related Threats