CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Vulnerability
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
- Severity
- critical
- Product
- Fortinet FortiClient EMS
- Published
- 2026-04-06
- EPSS
- 0.907
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2026-35616&type=repositories
- https://nvd.nist.gov/vuln/detail/CVE-2026-35616
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.