Cybersecurity — 2026-04-06

Fortinet Patches Critical Zero-Day in FortiClient EMS Under Active Exploitation

Fortinet released an emergency weekend patch for CVE-2026-35616 (CVSS 9.1), a pre-authentication API access bypass in FortiClient EMS allowing unauthenticated code execution. Researchers at Defused Cyber and watchTowr observed exploitation in the wild since at least March 31, with attacks targeting honeypots before the patch was available. Over 2,000 exposed FortiClient EMS instances are online, concentrated in the US and Germany. This is the second critical unauthenticated vulnerability in FortiClient EMS within weeks, following CVE-2026-21643.

Analysis
Two critical FortiClient EMS zero-days within weeks suggest a systemic product weakness rather than isolated bugs. With 2,000+ exposed instances online and exploitation observed since March 31, the window between weaponization and patching was at least four days, ample time for initial access brokers to establish persistence on enterprise networks managing endpoint security.
3 sources
  1. Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS - The Hacker News
  2. New FortiClient EMS flaw exploited in attacks, emergency patch released - Bleeping Computer
  3. FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616) - Help Net Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE