CVE-2026-35616
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
- Published Apr 4, 2026
- CVSS 9.8 critical
- 9.1% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Quantifying 2026 Routinely Targeted Vulnerabilities (So Far) VulnCheck Blog ·