Pandorex
Security

Critical FortiClient EMS Zero-Day Exploited in the Wild – CISA Demands Immediate Patching

Published Pandorex Redaktion·4 min read
—

Fortinet released an emergency patch over the weekend for a critical vulnerability in FortiClient Enterprise Management Server (EMS). The flaw, tracked as CVE-2026-35616, allows unauthenticated attackers to execute arbitrary code via crafted requests, earning a critical CVSS 9.1 rating.

Active Exploitation Since Late March

Fortinet confirmed the vulnerability is being exploited in the wild. Security firm watchTowr reported that its honeypot infrastructure first captured exploitation attempts on March 31. According to watchTowr's Ryan Dewhurst, initial exploitation was "low and slow" but quickly escalated to opportunistic, indiscriminate attacks.

CISA Sets Deadline

The US CISA added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog on Monday, setting a Thursday deadline for all federal agencies to apply the patch.

Affected Versions and Patch

  • Affected: FortiClient EMS 7.4.5 and 7.4.6
  • Fix: Hotfix via Fortinet PSIRT advisory FG-IR-26-099

VulnCheck VP Caitlin Condon noted that FortiClient EMS has a relatively small internet-facing footprint, with roughly 100 exposed instances observed.

Second Critical FortiClient Flaw in Weeks

This is the second critical FortiClient vulnerability in recent weeks. In late March, CVE-2026-21643 was also found to be under active exploitation, likewise allowing unauthenticated remote code execution.

State-backed threat actors from Russia and China have previously targeted vulnerable FortiClient EMS instances.

Sources: The Register, Fortinet PSIRT, CISA KEV Catalog

Comments

Sign in to write a comment.

Swipe up
Next Article

AI Agent Hacks FreeBSD in 4 Hours: Claude Autonomously Writes Two Kernel Exploits

Security