Vulnerability record · CVE-2026-35616 · published 4 April 2026
CVE-2026-35616: FortiClientEMS improper access control allows unauthenticated code execution
Fortinet · Forticlientems
Fortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted requests to execute unauthorized code or commands. It is remotely reachable with no privileges or user interaction, and CISA added it to KEV with a three-day remediation deadline, so it warrants immediate action.
Description
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, active KEV listing and near-maximum EPSS probability makes this an urgent patch-first case.
What it is
Fortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted requests to execute unauthorized code or commands. It is remotely reachable with no privileges or user interaction, and CISA added it to KEV with a three-day remediation deadline, so it warrants immediate action.
Impact
An unauthenticated attacker can run arbitrary code or commands on the FortiClientEMS server, gaining full control of the host and any data or downstream endpoints it manages.
Attack surface
Reachable over the network via crafted HTTP requests to the FortiClientEMS service; the CVSS vector shows no authentication (PR:N) and no user interaction (UI:N) required.
Exploitation
Listed in CISA KEV on 2026-04-06 with a 2026-04-09 due date, indicating known exploitation in the wild; EPSS 30-day probability is 0.90749 (99.8th percentile). No ransomware campaign use is documented.
What to do
- Apply the Fortinet patch per FG-IR-26-099 immediately; this is the primary fix.
- If patching is not possible, apply the vendor's stated mitigations or discontinue use of the product, per CISA's required action.
- Restrict network access to the FortiClientEMS management interface to trusted hosts only.
- Monitor for and block crafted requests targeting the EMS service until remediation is complete.
- Verify remediation against CISA BOD 22-01 guidance for cloud services if the instance is cloud-hosted.
Detection
- Review FortiClientEMS and web server logs for anomalous or malformed requests, especially those preceding unexpected process or command execution.
- Alert on unexpected child processes or command shells spawned by the FortiClientEMS service.
- Monitor for outbound connections from the EMS host to unfamiliar destinations that could indicate post-exploitation activity.
- Audit EMS configuration and accounts for unauthorized changes following any suspicious request activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-35616 to the Known Exploited Vulnerabilities catalog on 6 April 2026 as "Fortinet FortiClient EMS Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 April 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-099 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35616 | US Government Resource |
Track CVE-2026-35616 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-35616), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.