FortiClient EMS Gets a Second Zero-Day in One Week — CVE-2026-35616 Is Already Being Exploited

Same product, different vulnerability class, same outcome: unauthenticated RCE on your endpoint management server. Exploitation started Easter weekend.

FortiClient EMS Gets a Second Zero-Day in One Week — CVE-2026-35616 Is Already Being Exploited

If you patched FortiClient EMS after our last blog post on CVE-2026-21643 and thought you were done — you're not.

A new zero-day just dropped. Same product, different vulnerability class, same outcome: unauthenticated remote code execution on your endpoint management server.

CVE-2026-35616: What It Is

An improper access control flaw (CWE-284) in the FortiClient EMS API layer. An unauthenticated attacker can send crafted requests to bypass all API authentication and authorization checks — no credentials, no user interaction, no elevated privileges required.

CVSS 9.1. Network-based, low complexity, full impact on confidentiality, integrity, and availability.

Defused Cyber discovered active exploitation earlier this week and reported it to Fortinet under responsible disclosure. watchTowr confirmed their honeypots recorded exploitation attempts dating back to March 31 — Easter weekend. Fortinet published the advisory (FG-IR-26-099) and released emergency hotfixes on April 4.

DetailValue
CVECVE-2026-35616
CVSS9.1 (Critical)
TypePre-auth API access bypass → privilege escalation
CWECWE-284 (Improper Access Control)
AffectedFortiClient EMS 7.4.5, 7.4.6
Not affectedFortiClient EMS 7.2.x
FixHotfix available for 7.4.5 and 7.4.6; permanent fix in upcoming 7.4.7
Discovered bySimo Kohonen (Defused Cyber), Nguyen Duc Anh

Two Critical Vulnerabilities, One Product, One Week

Here's the timeline:

  • CVE-2026-21643 — SQL injection in FortiClient EMS, patched in February, first exploitation detected March 25, public PoC and active scanning by late March
  • CVE-2026-35616 — API access bypass in FortiClient EMS, zero-day exploitation observed March 31, advisory published April 4

Both are unauthenticated. Both target the same product. Both are confirmed exploited in the wild. Whether the same threat actor is behind both is still unknown — but the timing suggests this isn't coincidental.

watchTowr's CEO put it plainly: attackers know holiday weekends are when security teams are at half strength. The window between compromise and detection stretches from hours to days. Easter was that window.

2,000+ Instances Still Exposed

Shadowserver identified over 2,000 FortiClient EMS instances publicly accessible on the internet. The US and Germany lead the exposure list.

FortiClient EMS isn't just another management console. It's the central platform that manages Fortinet VPN clients, pushes security policies, and controls endpoint configurations across entire organizations. Compromise EMS and you can manipulate endpoint configurations, push malicious updates, harvest VPN credentials, and establish persistence across the fleet.

What To Do

If you're running FortiClient EMS 7.4.5 or 7.4.6:

  1. Install the hotfix immediately
  2. Restrict internet-facing access to EMS — this should never be directly exposed
  3. Check your logs for unusual unauthenticated API requests, especially from March 31 onward
  4. Don't forget CVE-2026-21643 — if you only patched one, you're still vulnerable to the other

If you're on FortiClient EMS 7.2.x: You're not affected by this specific CVE, but stay on top of updates.

The Pattern Continues

This is the third FortiClient EMS vulnerability to be actively exploited in 2026. Combined with the Cisco IMC, Cisco SSM, and F5 BIG-IP vulnerabilities we've covered recently — the message is clear: enterprise management tools are the primary target.

The tools that manage your endpoints are more valuable to attackers than the endpoints themselves. If you're not tracking vulnerabilities in your management infrastructure with the same urgency as your production systems, that gap is what attackers are counting on.