CVE-2026-35616
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Severity
Critical 9.1
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Apr 6, 2026
EPSS
0.889
99.8th percentile
Discovered by
Not disclosed
Published
Apr 4, 2026
Assigned by fortinet
Description
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Weakness: CWE-284
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiClientEMS
Vendor remediation
Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.7 or above