🔴 CVE-2026-35616

Critical unauthenticated remote code execution vulnerability in Fortinet FortiClient EMS management server. Allows attackers to execute arbitrary code via crafted network requests without authentication.

← Back to Overview
HIGH_RISK
Risk Level
9.1
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-04-04

Added to CISA KEV: 2026-04-06 2 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-04-06)

CVE-2026-35616 is a vulnerability affecting Fortinet FortiClient EMS versions 7.4.5 through 7.4.6 [1]. It is an improper access control vulnerability that may allow an unauthenticated attacker to execute arbitrary code [1].

Regarding its exploitation:

  • Active Exploitation: There is evidence of active exploitation of CVE-2026-35616 [2]. It was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on April 1, 2026, due to this active exploitation [3].
  • Internet-Facing Applications: While the specific details of how this vulnerability is being exploited in relation to internet-facing applications are not explicitly stated, vulnerabilities in endpoint management solutions like FortiClient EMS can often be targeted through network access, potentially affecting internet-facing services if not properly secured.
  • Attack Vectors and Exploitation Methods: The vulnerability allows an unauthenticated attacker to execute arbitrary code [1]. Further technical details on the specific attack vectors and exploitation methods are not provided in the available information.
  • Targeted Attacks: It is not currently known if the same threat actor is behind the exploitation of CVE-2026-35616 and another recently patched FortiClient EMS vulnerability (CVE-2026-21643), or if they are being weaponized together [2].
  • CISA Known Exploited Vulnerabilities (KEV) Status: CVE-2026-35616 is listed in CISA's Known Exploited Vulnerabilities (KEV) Catalog [3]. This catalog is maintained by CISA as an authoritative source of vulnerabilities that have been exploited in the wild, and organizations are encouraged to use it for vulnerability management prioritization [4].
  • Technical Details about Internet Exploitability: The vulnerability is described as an improper access control issue [1]. This type of vulnerability can often be exploited remotely if the affected component is accessible over a network. However, specific technical details regarding the exploitability over the internet are not detailed in the provided sources.

Sources

  1. CVE-2026-35616 Detail - NVD

    A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute ...

  2. Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

    The development comes merely days after another recently-patched, critical vulnerability in FortiClient EMS (CVE-2026-21643, CVSS score: 9.1) came under active exploitation. It's currently not known if the same threat actor is behind the exploitation of both the flaws, and if they are being weaponiz…

  3. CISA Adds One Known Exploited Vulnerability to Catalog

    This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known C…

  4. Known Exploited Vulnerabilities Catalog - CISA

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catal…