FortiClient improper access control exposes users' VPN credentialsSecurity Affairs·Dec 14, 13:28 UTC · Dec 14, 2017Exploit / PoCCVE-2017-1418460
U.S. CISA adds a flaw in Fortinet FortiClient EMS to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 7, 09:02 UTC · Apr 7, 2026Exploit / PoC in the wildCVE-2026-3561660
China-linked actor's malware DeepData exploits FortiClient VPN zero-daySecurity Affairs·Nov 19, 15:08 UTC · Nov 19, 2024Exploit / PoC60
FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)Help Net Security·Jun 24, 10:28 UTC · Jun 24, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-2164360
CISA adds FortiClient EMS, Ivanti EPM CSA, Nice Linear eMerge E3-Series bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 25, 20:52 UTC · Mar 25, 2024Exploit / PoC in the wildCVE-2023-48788CVE-2021-44529CVE-2019-725660
Critical Fortinet's FortiClient EMS flaw actively exploited in the wildSecurity Affairs·Mar 23, 08:58 UTC · Mar 23, 2024Exploit / PoC in the wildCVE-2023-4878860
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploitedHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-21643CVE-2026-20093+2 CVEs160
Critical FortiClient EMS vulnerability fixed, (fake?) PoC for sale (CVE-2023-48788)Help Net Security·Apr 15, 08:17 UTC · Apr 15, 2024Exploit / PoC in the wildCVE-2023-4878860
Fortinet customers confront actively exploited zeroCyberScoop·Apr 6, 21:12 UTC · Apr 6, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-2164360
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe SoftwareThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Exploit / PoC in the wildCVE-2026-21643CVE-2020-9715CVE-2023-36424+3 CVEs60
Singapore, US warn of latest Fortinet bug being exploited in wildThe Record·Apr 6, 16:25 UTC · Apr 6, 2026Exploit / PoC in the wildCVE-2026-3561660
Hackers Exploit Fortinet Flaw, Deploy ScreenConnect, Metasploit in New CampaignThe Hacker News·Apr 18, 14:09 UTC · Apr 18, 2024Exploit / PoCCVE-2023-4878860
NextGen Healthcare Mirth Connect Under AttackThe Hacker News·May 21, 16:00 UTC · May 21, 2024Exploit / PoC in the wildCVE-2023-43208CVE-2023-37679CVE-2024-1709+5 CVEs60
CISA adds Microsoft SharePoint bug disclosed at Pwn2Own to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 11, 21:44 UTC · Apr 11, 2024Exploit / PoC in the wildCVE-2023-24955CVE-2023-48788CVE-2021-44529+1 CVEs60