CVE-2026-35616

critical Fortinet ⚠️ CISA KEV — Exploited in the Wild
CVSS v3 Base Score
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
EPSS Score
25.3%
Exploitation probability in 30 days
Top 4% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Published: April 4, 2026 (40 days ago)
Last Modified: April 21, 2026
Vendor: Fortinet
Source: MITRE

⚠️ CISA Known Exploited Vulnerability

Added to KEV: 2026-04-06
Remediation Due: 2026-04-09 (⚠ 35d overdue)

Description

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

CWE

CWE-284

Affected Products

Fortinet FortiClientEMS

References