← Vulnerability feed

Vulnerability record · CVE-2026-35616 · published 4 April 2026

CVE-2026-35616: FortiClientEMS improper access control allows unauthenticated code execution

Fortinet · Forticlientems

Fortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted requests to execute unauthorized code or commands. It is remotely reachable with no privileges or user interaction, and CISA added it to KEV with a three-day remediation deadline, so it warrants immediate action.

9.8 CVSS 3.1 Critical CISA KEV since 6 Apr 2026 EPSS 9.1% · top 4.9% CWE-284 · Improper access control
9.8CVSS 3.1 base score
9.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
24 Jul 2026Last modified by NVD

Description

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, active KEV listing and near-maximum EPSS probability makes this an urgent patch-first case.

What it is

Fortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted requests to execute unauthorized code or commands. It is remotely reachable with no privileges or user interaction, and CISA added it to KEV with a three-day remediation deadline, so it warrants immediate action.

Impact

An unauthenticated attacker can run arbitrary code or commands on the FortiClientEMS server, gaining full control of the host and any data or downstream endpoints it manages.

Attack surface

Reachable over the network via crafted HTTP requests to the FortiClientEMS service; the CVSS vector shows no authentication (PR:N) and no user interaction (UI:N) required.

Exploitation

Listed in CISA KEV on 2026-04-06 with a 2026-04-09 due date, indicating known exploitation in the wild; EPSS 30-day probability is 0.90749 (99.8th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Fortinet patch per FG-IR-26-099 immediately; this is the primary fix.
  • If patching is not possible, apply the vendor's stated mitigations or discontinue use of the product, per CISA's required action.
  • Restrict network access to the FortiClientEMS management interface to trusted hosts only.
  • Monitor for and block crafted requests targeting the EMS service until remediation is complete.
  • Verify remediation against CISA BOD 22-01 guidance for cloud services if the instance is cloud-hosted.

Detection

  • Review FortiClientEMS and web server logs for anomalous or malformed requests, especially those preceding unexpected process or command execution.
  • Alert on unexpected child processes or command shells spawned by the FortiClientEMS service.
  • Monitor for outbound connections from the EMS host to unfamiliar destinations that could indicate post-exploitation activity.
  • Audit EMS configuration and accounts for unauthorized changes following any suspicious request activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-35616 to the Known Exploited Vulnerabilities catalog on 6 April 2026 as "Fortinet FortiClient EMS Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 April 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-35616 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-21643FortiClientEMS SQL injection allows unauthenticated remote code executionFortiClientEMS 7.4.4 fails to neutralize special elements in SQL commands, exposing a SQL injection reachable through crafted HTTP requests. Because …KEVEPSS 94%analysed9.8CVE-2026-59836Fortinet forticlientems improper certificate validation vulnerabilityA improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.…EPSS 0.22%9.8CVE-2024-23106Fortinet forticlientems improper restriction of authentication attempts vulnerabilityAn improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unau…EPSS 0.96%7.2CVE-2025-59922Fortinet forticlientems sql injection vulnerabilityAn improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientE…EPSS 7.8%6.7CVE-2026-39809Fortinet forticlientems sql injection vulnerabilityA improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, …EPSS 0.20%6.1CVE-2019-16149Fortinet forticlientems cross-site scripting vulnerabilityAn Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized co…EPSS 0.28%5.5CVE-2026-39810Fortinet forticlientems vulnerabilityA use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via d…EPSS 0.15%5.3CVE-2025-22859Fortinet forticlientems relative path traversal vulnerabilityA Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remot…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2026-35616), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.