LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-35616: Fortinet FortiClient EMS Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 6, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 9, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-35616 to its Known Exploited Vulnerabilities catalog on Apr 6, 2026, with a federal patch deadline of Apr 9, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

This vulnerability affects Fortinet FortiClient EMS and stems from improper access control. An unauthenticated attacker may be able to run unauthorized code or commands by sending crafted requests to the server. The issue is relevant for organizations that rely on the product to manage endpoints because successful exploitation could grant an attacker control over management functions.

How it works

The weakness is categorized as CWE-284, improper access control. In this class of flaw, the application fails to enforce authentication or authorization checks on certain functions or endpoints.

An attacker can abuse the condition by issuing requests that the server processes without verifying the sender's identity or permissions, resulting in execution of code or commands outside the intended scope.

Am I affected? How to find it in your systems

FortiClient EMS typically runs as a centralized management server for endpoint agents. Inventory all instances by reviewing network diagrams, asset management records, and any cloud-hosted deployments that match the product name.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary step. After patching, review and tighten access control settings on the EMS server to ensure only authenticated and authorized management traffic is permitted.

If you can't patch immediately

Follow the mitigations documented in the vendor advisory. Where the deployment involves cloud services, apply any relevant requirements from CISA BOD 22-01. If mitigations cannot be implemented, consider discontinuing use of the affected instance until an update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to unauthorized access and subsequent data exposure. Organizations can run a free exposure scan of their email addresses against known breach data to check for prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiClient EMS
WeaknessCWE-284
Added to CISA KEVApr 6, 2026
Federal patch deadlineApr 9, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities