Critical SEVERITY — Vulnerability

CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Platform
FortiGate / FortiOS
CVE Record
CVE-2026-35616
Advisory
CISA-KEV
Published
06 April 2026
Views
33
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Status

Bu açık CISA tarafından aktif istismar edildiği doğrulanmış açıklar katalogunda yer alıyor. Teorik bir risk değil — sahada kullanılıyor.

Description

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Details

  • Vendor: Fortinet
  • Product: FortiClient EMS
  • Katalog'a eklenme: 2026-04-06

CISA'nın Zorunlu Kıldığı Aksiyon

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

  • Due date for federal agencies: 2026-04-09
Fortinet FortiClient EMS

FortiGate / FortiOS — Related Advisories

VIEW ALL →