Fortinet Ships Emergency Patch for Actively Exploited FortiClient EMS Zero-Day CVE-2026-35616 (CVSS 9.1)
An unauthenticated RCE flaw in FortiClient EMS 7.4.5 and 7.4.6 has been actively exploited since March 31. Fortinet released out-of-band hotfixes on April 4 — upgrade now or workaround immediately.
Fortinet released emergency out-of-band hotfixes on April 4, 2026 for CVE-2026-35616, a pre-authentication API access bypass in FortiClient EMS that scores CVSS 9.1. Active exploitation was detected in the wild on March 31 — three days before Fortinet published the advisory.
What the Vulnerability Does
The flaw lives in the management API of FortiClient EMS versions 7.4.5 and 7.4.6. An unauthenticated remote attacker can send a crafted HTTP request to bypass authentication entirely and execute arbitrary code on the underlying server. No credentials required. No user interaction required. Full compromise from the network perimeter.
Security firm Defused Cyber first spotted exploitation activity in their honeypots on March 31. Shadowserver’s scanning data puts more than 2,000 FortiClient EMS instances directly exposed to the internet, with the highest concentrations in the United States and Germany.
Affected and Safe Versions
| Version | Status |
|---|---|
| FortiClient EMS 7.4.6 | Vulnerable |
| FortiClient EMS 7.4.5 | Vulnerable |
| FortiClient EMS 7.4.7 | Fixed (full release) |
| FortiClient EMS 7.2.x | Not affected |
The permanent fix ships in 7.4.7. Fortinet also pushed hotfix builds for 7.4.5 and 7.4.6 on April 4 for environments that cannot upgrade immediately.
What to Do Right Now
- Upgrade to FortiClient EMS 7.4.7 — the only version with the complete patch. Apply the April 4 hotfix if you cannot upgrade to 7.4.7 today.
- Block public internet access to the FortiClient EMS management port. This instance should never be directly internet-exposed.
- Audit logs from March 31 onward. Exploitation leaves anomalous requests to the management API. Look for unauthenticated calls that should require credentials.
- If you are on 7.2.x, you are not affected — but check whether your upgrade path to 7.4.x skips a vulnerable intermediate version.
The Broader Pattern
This is the third critical Fortinet management-plane vulnerability in 18 months to see active exploitation before or shortly after the advisory dropped. CVE-2024-47575 (FortiManager, CVSS 9.8) and CVE-2025-32756 (FortiVoice, CVSS 9.6) followed the same arc: honeypot detection → delayed disclosure → rushed patch. The trend is consistent: Fortinet perimeter products are a high-value target, and threat actors have their own intelligence pipeline that often runs ahead of public disclosure.
The gap between March 31 exploitation and the April 4 hotfix — four days — is not unusual in incident response timelines. But 2,000 exposed management surfaces is a lot of unclosed attack windows.
Who Is Exploiting It
No public attribution has been published as of April 6. Fortinet’s advisory does not name a threat actor. Given the pattern of prior Fortinet exploitation campaigns — notably UNC3569 targeting FortiGate devices for espionage purposes — organizations in defense, critical infrastructure, and financial services should treat unpatched FortiClient EMS systems as likely compromised until proven otherwise.
Patch today. Assume breach, investigate logs, and isolate the management plane.
Related reading
- Cybersecurity CVE-2026-42897 (CVSS 8.1): Microsoft Exchange OWA Zero-Day Actively Exploited — No Patch Available
- Cybersecurity CISA Adds 8 Actively Exploited Flaws to KEV, Including Three Cisco SD-WAN Zero-Days
- Cybersecurity Adobe Patches Actively Exploited Acrobat Reader Zero-Day CVE-2026-34621 — CISA Orders Federal Patch by April 27