CVE-2026-35616: Fortinet FortiClient EMS Improper Access Control Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-04-06. EPSS: 9.1% chance of exploitation in the next 30 days.
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Affected products
- Fortinet FortiClient EMS: version 7.4.5 only; version 7.4.6 only
Published 2026-04-04. Last modified 2026-07-24.