{"id":11877,"date":"2026-04-05T10:03:40","date_gmt":"2026-04-05T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/05\/critical-fortinet-forticlient-ems-0-day-vulnerability-actively-exploited-in-the-wild\/"},"modified":"2026-04-05T10:03:40","modified_gmt":"2026-04-05T10:03:40","slug":"critical-fortinet-forticlient-ems-0-day-vulnerability-actively-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/05\/critical-fortinet-forticlient-ems-0-day-vulnerability-actively-exploited-in-the-wild\/","title":{"rendered":"Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild"},"content":{"rendered":"<p>    Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Fortinet has issued an emergency hotfix after security researchers disclosed a critical zero-day vulnerability in FortiClient EMS that is already being actively exploited by threat actors.<\/p>\n<p>Tracked as CVE-2026-35616 and carrying a CVSSv3 score of 9.1 (Critical), the flaw enables unauthenticated attackers to <a href=\"https:\/\/cybersecuritynews.com\/authentication-bypass-better-auth-api-keys\/\" target=\"_blank\" rel=\"noreferrer noopener\">bypass API authentication<\/a> and authorization controls entirely, allowing them to execute arbitrary code or commands on vulnerable systems.<\/p>\n<p>The vulnerability, classified under CWE-284 (Improper Access Control), resides in the API layer of FortiClient Endpoint Management Server (EMS).<\/p>\n<p>Successful exploitation does not require any prior authentication, user interaction, or elevated privileges, making it particularly dangerous for organizations with internet-exposed EMS deployments.<\/p>\n<p>An unauthenticated remote attacker can send specially crafted API requests to bypass all authentication and authorization checks, effectively gaining full control over endpoint management operations.<\/p>\n<p>The attack vector is network-based, the complexity is low, and the impact spans confidentiality, integrity, and availability conditions that directly account for its near-maximum CVSS rating.<\/p>\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-099\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Fortinet\u2019s advisory (FG-IR-26-099) lists<\/a> the vulnerability\u2019s primary impact as <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">privilege e<\/span>scalation, with active in-the-wild exploitation confirmed by the vendor.<\/p>\n<h2 class=\"wp-block-heading\" id=\"affected-versions\"><strong>Fortinet FortiClient EMS 0-Day<\/strong><\/h2>\n<p>Only FortiClient EMS versions 7.4.5 and 7.4.6 are affected. FortiClient EMS 7.2. x is not affected and requires no action. The upcoming FortiClient EMS 7.4.7 will include a permanent fix, but Fortinet has made emergency hotfixes available immediately for both affected branches while that release is finalized.<\/p>\n<p>The vulnerability was discovered by Simo Kohonen from threat intelligence firm Defused and independent researcher Nguyen Duc Anh.<\/p>\n<p>Defused observed active in-the-wild exploitation of the flaw earlier this week before reporting it to Fortinet under responsible disclosure protocols. The discovery was made using Defused\u2019s upcoming Radar feature, set to launch next week, which is designed to surface novel exploitation activity in real time.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1f6a8.png?ssl=1\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> New Fortinet vulnerability being exploited as an 0-day <\/p>\n<p>CVE-2026-35616 \u2013 FortiClient EMS pre-authentication API access bypass \u2013 CVSS 9.1 Critical<\/p>\n<p>After observing in-the-wild exploitation of this vulnerability earlier this week, Defused reported it to Fortinet under\u2026 <a href=\"https:\/\/t.co\/GUk5fCAx91\">pic.twitter.com\/GUk5fCAx91<\/a><\/p>\n<p>\u2014 Defused (@DefusedCyber) <a href=\"https:\/\/twitter.com\/DefusedCyber\/status\/2040315969159995847?ref_src=twsrc%5Etfw\">April 4, 2026<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p>Upon receiving the report, Fortinet moved swiftly, publishing its advisory and releasing the emergency hotfix on April 4, 2026, the same day as initial publication.<\/p>\n<p>Fortinet strongly urges all customers running affected versions to apply the emergency hotfix immediately. Detailed installation instructions are available through the official FortiClient EMS release notes for each affected build:<\/p>\n<ul class=\"wp-block-list\">\n<li>FortiClient EMS 7.4.5: Follow hotfix instructions in the 7.4.5 EMS release notes via the Fortinet documentation portal<\/li>\n<li>FortiClient EMS 7.4.6: Follow hotfix instructions in the 7.4.6 EMS release notes via the Fortinet documentation portal<\/li>\n<\/ul>\n<p>Organizations should also monitor their EMS logs for anomalous API activity, particularly unauthenticated requests that may indicate prior exploitation attempts.<\/p>\n<p>Where possible, restricting external access to the EMS management interface at the network perimeter adds a meaningful layer of defense while patching is completed.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fortinet-forticlient-ems-0-day\/\">Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fortinet-forticlient-ems-0-day\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild Fortinet has issued an emergency hotfix after security researchers disclosed a critical zero-day vulnerability in FortiClient EMS that is already being actively exploited by threat actors. Tracked as CVE-2026-35616 and carrying a CVSSv3 score of 9.1 (Critical), the flaw enables unauthenticated attackers to bypass [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,648],"tags":[130],"class_list":["post-11877","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11877"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11877"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11877\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11877"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11877"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11877"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}