ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Fortinet customers confront actively exploited zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-35616CVE-2026-21643

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21643
Unauthenticated SQL Injection to Code Execution in Fortinet FortiClient EMS 7.4.4

CVE-2026-21643 is a critical SQL injection flaw (CWE-89, improper neutralization of special elements used in an SQL command) in Fortinet FortiClient EMS 7.4.4, scored 9.8 critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An unauthenticated remote attacker can trigger it by sending specifically crafted HTTP requests to the EMS server, and successful injection allows execution of unauthorized code or commands, yielding high confidentiality, integrity, and availability impact. Any organization running the affected FortiClient EMS release is exposed, with internet-facing EMS management servers at greatest risk. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-04-13, EPSS assigns a 94.1% probability of exploitation within 30 days (99.9th-plus percentile), and news reports describe active zero-day exploitation that prompted Fortinet to issue emergency patches, alongside related FortiClient EMS hotfixes (CVE-2026-35616).

Do: Upgrade affected FortiClient EMS 7.4.4 deployments using the emergency patch/hotfix Fortinet has released (see the Fortinet PSIRT advisory for fixed builds), prioritizing internet-exposed EMS servers; federal agencies must satisfy the BOD 22-01 requirement per the KEV listing. Until patched, restrict public exposure of the EMS web interface and review web access and database logs for signs of crafted HTTP requests or unexpected command execution.

9.894% KEV PoC
  • Fortinet FortiClient EMS 7.4.4 (version listed by CISA; fixed builds per the Fortinet PSIRT advisory/emergency patch)
largeon the order of tens of thousands of FortiClient EMS server deployments (estimate)
CVE-2026-35616
Unauthenticated Code Execution in Fortinet FortiClient EMS 7.4.5–7.4.6

Fortinet FortiClient EMS versions 7.4.5 through 7.4.6 contain an improper access control flaw (CWE-284) that allows an unauthenticated attacker to execute unauthorized code or commands by sending crafted requests over the network. The attack requires no authentication, privileges, or user interaction, making any reachable EMS management server a direct target. A successful attacker gains code execution on the EMS host, and reported campaigns have used the flaw to deploy a credential stealer. Any organization running FortiClient EMS 7.4.5 or 7.4.6 is affected. The flaw is being exploited in the wild: it was added to CISA KEV on 2026-04-06, carries a 90.7% EPSS probability of exploitation within 30 days, and Fortinet has released emergency hotfixes.

Do: Upgrade FortiClient EMS off 7.4.5/7.4.6 using the fixed release or emergency hotfix per Fortinet's advisory (the available data does not specify the fixed version number), prioritizing internet-exposed servers; U.S. federal agencies must follow BOD 22-01. Until patched, restrict EMS management access to trusted networks or VPN and monitor for credential-stealer activity on managed endpoints. Given confirmed in-the-wild exploitation, assume possible compromise and hunt for indicators on both EMS hosts and endpoints it manages.

9.891% KEV
  • Fortinet FortiClient EMS 7.4.5 through 7.4.6
large≈10,000–100,000 EMS deployments (order-of-magnitude estimate; exact counts not in the data)
Full article692 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Two critical defects in FortiClient EMS have been exploited in the past couple weeks. Experts push for users to apply an immediate hotfix.

Listen to this article

0:00

Learn more.

(Getty Images)

Fortinet released an emergency software update over the weekend to address an actively exploited vulnerability in FortiClient EMS, an endpoint management tool for customer devices.

The zero-day vulnerability — CVE-2026-35616 — has a CVSS rating of 9.8 and was added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerability catalog Monday. 

Fortinet said in a Saturday security advisory that it has seen the vulnerability being actively exploited in the wild.  The company issued a hotfix and plans to release a more comprehensive software update later, though that update is not yet available.

The security vendor did not say when the earliest known exploit occurred nor how many instances have already been impacted. 

Unknown attackers were first observed attempting to exploit the vulnerability March 31, Benjamin Harris, founder and CEO at watchTowr, told CyberScoop. 

“Exploitation attempts and probes were initially limited, reflecting typical attacker desire to try and keep usage of a zero-day from discovery and observation,” he added. “As of April 6, given attention and Fortinet issuing a hotfix, exploitation has ramped up, indicating growing attacker interest and likely broader targeting.”

Shadowserver scans found nearly 2,000 publicly exposed instances of FortiClient EMS on Sunday. It’s unclear how many of those instances are running vulnerable versions of the software.

The recently discovered zero-day shares similarities with CVE-2026-21643, another unauthenticated FortiClient EMS defect that Fortinet disclosed Feb. 6. The vendor and cyber authorities last week warned that CVE-2026-21643 has been exploited in the wild. 

Researchers have yet to find any significant link between the vulnerabilities or attribute the attacks to known threat actors, but both defects were actively exploited in a short timeframe and both allow attackers to execute code remotely. 

“Fortinet solutions are popular targets for threat actors generally, so exploitation isn’t necessarily surprising,” said Caitlin Condon, vice president of security research at VulnCheck.

CISA has added 10 Fortinet defects to its known exploited vulnerabilities catalog since early 2025. 

While there is no full patch for CVE-2026-35616, Harris credited Fortinet for rushing out a hotfix over a holiday weekend, adding that it reflects how urgently the company is treating the matter. 

“The timing of the ramp-up of in-the-wild exploitation of this zero-day is likely not coincidental,” he said. “Attackers have shown repeatedly that holiday weekends are the best time to move. Security teams are at half strength, on-call engineers are distracted, and the window between compromise and detection stretches from hours to days. Easter, like any other holiday, represents opportunity.”

A Fortinet spokesperson said response and remediation efforts are ongoing and the company is communicating directly with customers to advise on necessary actions.

“The best time to apply the hotfix was yesterday,” Harris said. “The second-best time is right now.”

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/fortinet-forticlient-ems-zero-day-cve-2026-35616-hotfix-known-exploited/