Cybersecurity — 2026-04-06
Fortinet Patches Critical Zero-Day in FortiClient EMS Under Active Exploitation
Fortinet released an emergency weekend patch for CVE-2026-35616 (CVSS 9.1), a pre-authentication API access bypass in
Analysis
Two critical FortiClient EMS zero-days within weeks suggest a systemic product weakness rather than isolated bugs. With 2,000+ exposed instances online and exploitation observed since March 31, the window between weaponization and patching was at least four days, ample time forinitial access brokers to establish persistence on enterprise networks managing endpoint security.
Two critical FortiClient EMS zero-days within weeks suggest a systemic product weakness rather than isolated bugs. With 2,000+ exposed instances online and exploitation observed since March 31, the window between weaponization and patching was at least four days, ample time for
3 sources
- Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS -
The Hacker News - New FortiClient EMS flaw exploited in attacks, emergency patch released -
Bleeping Computer - FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616) -
Help Net Security