Switch language한국어
Back to the list

Fortinet EMS Zero-Day CVE-2026-35616 Confirmed — Apply Hotfix Now

TL;DR AI

Key summary

2 min read
  1. Fortinet confirmed a pre-authentication API access bypass in FortiClientEMS that allows unauthorized code execution.

  2. The vulnerability CVE-2026-35616 has a CVSS score of 9.1 and is being actively exploited in the wild.

  3. Fortinet released an emergency hotfix for FortiClientEMS 7.4.5 and 7.4.6 and said version 7.4.7 will contain a permanent fix.

Read the original