ZeroHour

CVE-2026-35616

KEVlarge1

Unauthenticated Code Execution in Fortinet FortiClient EMS 7.4.5–7.4.6

CISA: Fortinet FortiClient EMS Improper Access Control Vulnerability

CVSS 3.1
9.8 critical
EPSS
91%p100
Published
()
KEV added
AI analysis

Fortinet FortiClient EMS versions 7.4.5 through 7.4.6 contain an improper access control flaw (CWE-284) that allows an unauthenticated attacker to execute unauthorized code or commands by sending crafted requests over the network. The attack requires no authentication, privileges, or user interaction, making any reachable EMS management server a direct target. A successful attacker gains code execution on the EMS host, and reported campaigns have used the flaw to deploy a credential stealer. Any organization running FortiClient EMS 7.4.5 or 7.4.6 is affected. The flaw is being exploited in the wild: it was added to CISA KEV on 2026-04-06, carries a 90.7% EPSS probability of exploitation within 30 days, and Fortinet has released emergency hotfixes.

What to do: Upgrade FortiClient EMS off 7.4.5/7.4.6 using the fixed release or emergency hotfix per Fortinet's advisory (the available data does not specify the fixed version number), prioritizing internet-exposed servers; U.S. federal agencies must follow BOD 22-01. Until patched, restrict EMS management access to trusted networks or VPN and monitor for credential-stealer activity on managed endpoints. Given confirmed in-the-wild exploitation, assume possible compromise and hunt for indicators on both EMS hosts and endpoints it manages.

Affected
Fortinet FortiClient EMS7.4.5 through 7.4.6
Estimated exposure
large≈10,000–100,000 EMS deployments (order-of-magnitude estimate; exact counts not in the data) — Fortinet's large enterprise footprint and EMS's role as the central management server for the widely deployed FortiClient endpoint agent — commonly reachable over the network for remote endpoint management — support a five-figure-scale…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

CISA Known Exploited Vulnerability
Affected
Fortinet FortiClient EMS
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
fortinet
Products
forticlientems
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news