FortiClient EMS Gets a Second Zero-Day in One Week — CVE-2026-35616 Is Already Being Exploited
Same product, different vulnerability class, same outcome: unauthenticated RCE on your endpoint management server. Exploitation started Easter weekend.
If you patched FortiClient EMS after our last blog post on CVE-2026-21643 and thought you were done — you're not.
A new zero-day just dropped. Same product, different vulnerability class, same outcome: unauthenticated remote code execution on your endpoint management server.
CVE-2026-35616: What It Is
An improper access control flaw (CWE-284) in the FortiClient EMS API layer. An unauthenticated attacker can send crafted requests to bypass all API authentication and authorization checks — no credentials, no user interaction, no elevated privileges required.
CVSS 9.1. Network-based, low complexity, full impact on confidentiality, integrity, and availability.
Defused Cyber discovered active exploitation earlier this week and reported it to Fortinet under responsible disclosure. watchTowr confirmed their honeypots recorded exploitation attempts dating back to March 31 — Easter weekend. Fortinet published the advisory (FG-IR-26-099) and released emergency hotfixes on April 4.
| Detail | Value |
|---|---|
| CVE | CVE-2026-35616 |
| CVSS | 9.1 (Critical) |
| Type | Pre-auth API access bypass → privilege escalation |
| CWE | CWE-284 (Improper Access Control) |
| Affected | FortiClient EMS 7.4.5, 7.4.6 |
| Not affected | FortiClient EMS 7.2.x |
| Fix | Hotfix available for 7.4.5 and 7.4.6; permanent fix in upcoming 7.4.7 |
| Discovered by | Simo Kohonen (Defused Cyber), Nguyen Duc Anh |
Two Critical Vulnerabilities, One Product, One Week
Here's the timeline:
- CVE-2026-21643 — SQL injection in FortiClient EMS, patched in February, first exploitation detected March 25, public PoC and active scanning by late March
- CVE-2026-35616 — API access bypass in FortiClient EMS, zero-day exploitation observed March 31, advisory published April 4
Both are unauthenticated. Both target the same product. Both are confirmed exploited in the wild. Whether the same threat actor is behind both is still unknown — but the timing suggests this isn't coincidental.
watchTowr's CEO put it plainly: attackers know holiday weekends are when security teams are at half strength. The window between compromise and detection stretches from hours to days. Easter was that window.
2,000+ Instances Still Exposed
Shadowserver identified over 2,000 FortiClient EMS instances publicly accessible on the internet. The US and Germany lead the exposure list.
FortiClient EMS isn't just another management console. It's the central platform that manages Fortinet VPN clients, pushes security policies, and controls endpoint configurations across entire organizations. Compromise EMS and you can manipulate endpoint configurations, push malicious updates, harvest VPN credentials, and establish persistence across the fleet.
What To Do
If you're running FortiClient EMS 7.4.5 or 7.4.6:
- Install the hotfix immediately
- Restrict internet-facing access to EMS — this should never be directly exposed
- Check your logs for unusual unauthenticated API requests, especially from March 31 onward
- Don't forget CVE-2026-21643 — if you only patched one, you're still vulnerable to the other
If you're on FortiClient EMS 7.2.x: You're not affected by this specific CVE, but stay on top of updates.
The Pattern Continues
This is the third FortiClient EMS vulnerability to be actively exploited in 2026. Combined with the Cisco IMC, Cisco SSM, and F5 BIG-IP vulnerabilities we've covered recently — the message is clear: enterprise management tools are the primary target.
The tools that manage your endpoints are more valuable to attackers than the endpoints themselves. If you're not tracking vulnerabilities in your management infrastructure with the same urgency as your production systems, that gap is what attackers are counting on.