ZeroHour
The Recordpublished ()ingested

Singapore, US warn of latest Fortinet bug being exploited in wild

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-35616

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-35616
Unauthenticated Code Execution in Fortinet FortiClient EMS 7.4.5–7.4.6

Fortinet FortiClient EMS versions 7.4.5 through 7.4.6 contain an improper access control flaw (CWE-284) that allows an unauthenticated attacker to execute unauthorized code or commands by sending crafted requests over the network. The attack requires no authentication, privileges, or user interaction, making any reachable EMS management server a direct target. A successful attacker gains code execution on the EMS host, and reported campaigns have used the flaw to deploy a credential stealer. Any organization running FortiClient EMS 7.4.5 or 7.4.6 is affected. The flaw is being exploited in the wild: it was added to CISA KEV on 2026-04-06, carries a 90.7% EPSS probability of exploitation within 30 days, and Fortinet has released emergency hotfixes.

Do: Upgrade FortiClient EMS off 7.4.5/7.4.6 using the fixed release or emergency hotfix per Fortinet's advisory (the available data does not specify the fixed version number), prioritizing internet-exposed servers; U.S. federal agencies must follow BOD 22-01. Until patched, restrict EMS management access to trusted networks or VPN and monitor for credential-stealer activity on managed endpoints. Given confirmed in-the-wild exploitation, assume possible compromise and hunt for indicators on both EMS hosts and endpoints it manages.

9.891% KEV
  • Fortinet FortiClient EMS 7.4.5 through 7.4.6
large≈10,000–100,000 EMS deployments (order-of-magnitude estimate; exact counts not in the data)
Full article285 words · extracted from therecord.media · click to collapse

Government agencies in the U.S. and Singapore released urgent notices warning that a bug impacting a Fortinet tool is being exploited in attacks following a disclosure by cybersecurity researchers. 

The cybersecurity company Defused said it observed in-the-wild exploitation of CVE-2026-35616 last week and disclosed it to Fortinet. Fortinet explained in an advisory that the vulnerability carries a severity score of 9.1 out of 10 and urged customers to install a hotfix for the bug.  

The Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Thursday to apply the hotfix. 

“Please adhere to Fortinet's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Fortinet products affected by this vulnerability,” CISA said. “Apply any final mitigations provided by the vendor as soon as they become available.”

Researchers warned that FortiClient EMS is used widely across many governments around the world and exposure to the bug may be wide. 

Benjamin Harris, CEO of cybersecurity firm watchTowr, said their honeypots began capturing exploitation of CVE-2026-35616 on March 31. He credited Fortinet with quickly releasing a fix for the bug, reflecting how urgently the company treated the vulnerability. 

“The timing of the ramp-up of in-the-wild exploitation of this zero-day is likely not coincidental. Attackers have shown repeatedly that holiday weekends are the best time to move,” Harris noted. 

“Security teams are at half strength, on-call engineers are distracted, and the window between compromise and detection stretches from hours to days. Easter, like any other holiday, represents opportunity.” 

He added that this is the second vulnerability in FortiClient EMS disclosed over the last three weeks, meaning customers will again have to rush to patch their platforms before attackers gain the upper hand. 

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/singapore-us-warn-of-fortinet-bug-exploited