Fortinet released an emergency patch over the weekend for a critical vulnerability in FortiClient Enterprise Management Server (EMS). The flaw, tracked as CVE-2026-35616, allows unauthenticated attackers to execute arbitrary code via crafted requests, earning a critical CVSS 9.1 rating.
Active Exploitation Since Late March
Fortinet confirmed the vulnerability is being exploited in the wild. Security firm watchTowr reported that its honeypot infrastructure first captured exploitation attempts on March 31. According to watchTowr's Ryan Dewhurst, initial exploitation was "low and slow" but quickly escalated to opportunistic, indiscriminate attacks.
CISA Sets Deadline
The US CISA added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog on Monday, setting a Thursday deadline for all federal agencies to apply the patch.
Affected Versions and Patch
- Affected: FortiClient EMS 7.4.5 and 7.4.6
- Fix: Hotfix via Fortinet PSIRT advisory FG-IR-26-099
VulnCheck VP Caitlin Condon noted that FortiClient EMS has a relatively small internet-facing footprint, with roughly 100 exposed instances observed.
Second Critical FortiClient Flaw in Weeks
This is the second critical FortiClient vulnerability in recent weeks. In late March, CVE-2026-21643 was also found to be under active exploitation, likewise allowing unauthenticated remote code execution.
State-backed threat actors from Russia and China have previously targeted vulnerable FortiClient EMS instances.
Sources: The Register, Fortinet PSIRT, CISA KEV Catalog