ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-35616CVE-2026-21643

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21643
Unauthenticated SQL Injection to Code Execution in Fortinet FortiClient EMS 7.4.4

CVE-2026-21643 is a critical SQL injection flaw (CWE-89, improper neutralization of special elements used in an SQL command) in Fortinet FortiClient EMS 7.4.4, scored 9.8 critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An unauthenticated remote attacker can trigger it by sending specifically crafted HTTP requests to the EMS server, and successful injection allows execution of unauthorized code or commands, yielding high confidentiality, integrity, and availability impact. Any organization running the affected FortiClient EMS release is exposed, with internet-facing EMS management servers at greatest risk. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-04-13, EPSS assigns a 94.1% probability of exploitation within 30 days (99.9th-plus percentile), and news reports describe active zero-day exploitation that prompted Fortinet to issue emergency patches, alongside related FortiClient EMS hotfixes (CVE-2026-35616).

Do: Upgrade affected FortiClient EMS 7.4.4 deployments using the emergency patch/hotfix Fortinet has released (see the Fortinet PSIRT advisory for fixed builds), prioritizing internet-exposed EMS servers; federal agencies must satisfy the BOD 22-01 requirement per the KEV listing. Until patched, restrict public exposure of the EMS web interface and review web access and database logs for signs of crafted HTTP requests or unexpected command execution.

9.894% KEV PoC
  • Fortinet FortiClient EMS 7.4.4 (version listed by CISA; fixed builds per the Fortinet PSIRT advisory/emergency patch)
largeon the order of tens of thousands of FortiClient EMS server deployments (estimate)
CVE-2026-35616
Unauthenticated Code Execution in Fortinet FortiClient EMS 7.4.5–7.4.6

Fortinet FortiClient EMS versions 7.4.5 through 7.4.6 contain an improper access control flaw (CWE-284) that allows an unauthenticated attacker to execute unauthorized code or commands by sending crafted requests over the network. The attack requires no authentication, privileges, or user interaction, making any reachable EMS management server a direct target. A successful attacker gains code execution on the EMS host, and reported campaigns have used the flaw to deploy a credential stealer. Any organization running FortiClient EMS 7.4.5 or 7.4.6 is affected. The flaw is being exploited in the wild: it was added to CISA KEV on 2026-04-06, carries a 90.7% EPSS probability of exploitation within 30 days, and Fortinet has released emergency hotfixes.

Do: Upgrade FortiClient EMS off 7.4.5/7.4.6 using the fixed release or emergency hotfix per Fortinet's advisory (the available data does not specify the fixed version number), prioritizing internet-exposed servers; U.S. federal agencies must follow BOD 22-01. Until patched, restrict EMS management access to trusted networks or VPN and monitor for credential-stealer activity on managed endpoints. Given confirmed in-the-wild exploitation, assume possible compromise and hunt for indicators on both EMS hosts and endpoints it manages.

9.891% KEV
  • Fortinet FortiClient EMS 7.4.5 through 7.4.6
large≈10,000–100,000 EMS deployments (order-of-magnitude estimate; exact counts not in the data)
Full article242 words · extracted from helpnetsecurity.com · click to collapse

Defused has spotted a critical Fortinet FortiClient Endpoint Management Server (EMS) zero-day vulnerability (CVE-2026-35616) being exploited in the wild.

This time around, the confirmation of active exploitation came almost immediately from Fortinet, as well.

“Fortinet has observed [CVE-2026-35616] to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6,” the company stated in a security advisory published on Saturday.

About CVE-2026-35616

On Monday, Defused warned about CVE-2026-21643, a critical SQL injection vulnerability in Fortinet FortiClient EMS, being leveraged by remote, unauthenticated attackers.

The exploitation of CVE-2026-21643 came months after Fortinet pushed out a fix for it and several weeks after Bishop Fox researchers shared their analysis of the vulnerability and practical exploitation paths.

CVE-2026-35616, on the other hand, is an improper access control vulnerability that allows for an API authentication and authorization bypass, and may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

CVE-2026-35616 affects FortiClientEMS versions 7.4.5 and 7.4.6, but not the 7.2 branch. According to Fortinet, the provided hotfixes are “sufficient to prevent it entirely.”

“Upcoming FortiClientEMS 7.4.7 will also include a fix for this issue,” the company added. The security advisory does not mention whether the 8.0 branch is affected by this flaw.

It’s also unknown whether the two zero-days are being leveraged together.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/