CVE-2026-35616Active Exploitation(fortinet / forticlientems)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 126 mentions and remains active

Immediate actions

  • Patch fortinet forticlientems systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-09. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-284

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forticlientems

Threat summary

  • Active exploitation appears in 403 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 514 mentions across 62 observed days

What's happening

  • Active exploitation reported across 403 signals
  • Exploit tool or code specified in 14 signals
  • PoC mentioned or linked in 43 signals
  • Patch or workaround mentioned in 260 signals
  • Technical details provided in 292 signals
  • Disclosure: 41 classified signals
  • Peaked 59d ago at 126 mentions (2026-04-06); latest day: 1
  • 514 total mentions across 62 days

Affected systems

Vendors
Products
forticlientems

2 versions affected across 1 product

Deep dive

Activity timeline514 mentions / 62d
0326395126Mentions · 2026-04-04: 34Mentions · 2026-04-05: 80Mentions · 2026-04-06: 126Mentions · 2026-04-07: 62Mentions · 2026-04-08: 13Mentions · 2026-04-09: 7Mentions · 2026-04-10: 10Mentions · 2026-04-11: 2Mentions · 2026-04-12: 3Mentions · 2026-04-13: 8Mentions · 2026-04-14: 2Mentions · 2026-04-15: 11Mentions · 2026-04-18: 2Mentions · 2026-04-19: 1Mentions · 2026-04-20: 5Mentions · 2026-04-21: 6Mentions · 2026-04-22: 4Mentions · 2026-04-23: 1Mentions · 2026-04-24: 3Mentions · 2026-04-25: 1Mentions · 2026-04-27: 2Mentions · 2026-04-28: 1Mentions · 2026-04-29: 1Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Mentions · 2026-05-06: 7Mentions · 2026-05-07: 2Mentions · 2026-05-09: 5Mentions · 2026-05-11: 1Mentions · 2026-05-12: 2Mentions · 2026-05-13: 1Mentions · 2026-05-15: 6Mentions · 2026-05-21: 3Mentions · 2026-05-22: 2Mentions · 2026-05-27: 3Mentions · 2026-05-28: 26Mentions · 2026-05-29: 17Mentions · 2026-05-30: 5Mentions · 2026-05-31: 1Mentions · 2026-06-01: 4Mentions · 2026-06-03: 1Mentions · 2026-06-04: 1Mentions · 2026-06-05: 1Mentions · 2026-06-06: 1Mentions · 2026-06-08: 6Mentions · 2026-06-10: 2Mentions · 2026-06-11: 3Mentions · 2026-06-16: 3Mentions · 2026-06-17: 6Mentions · 2026-06-20: 1Mentions · 2026-06-25: 6Mentions · 2026-06-26: 1Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-07-15: 1Mentions · 2026-08-02: 1Mentions · 2026-08-27: 1Mentions · 2026-09-10: 1PoC Mentioned / Linked · 2026-04-04: 4PoC Mentioned / Linked · 2026-04-05: 2PoC Mentioned / Linked · 2026-04-06: 9PoC Mentioned / Linked · 2026-04-07: 5PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-21: 2PoC Mentioned / Linked · 2026-04-25: 1PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-09: 5PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-05-28: 4PoC Mentioned / Linked · 2026-05-29: 1PoC Mentioned / Linked · 2026-05-31: 1PoC Mentioned / Linked · 2026-06-01: 1Exploit Tool / Code · 2026-04-04: 1Exploit Tool / Code · 2026-04-06: 3Exploit Tool / Code · 2026-04-07: 1Exploit Tool / Code · 2026-04-25: 1Exploit Tool / Code · 2026-05-06: 1Exploit Tool / Code · 2026-05-07: 1Exploit Tool / Code · 2026-05-11: 1Exploit Tool / Code · 2026-05-15: 1Exploit Tool / Code · 2026-05-28: 3Exploit Tool / Code · 2026-06-01: 1Active Exploitation · 2026-04-04: 24Active Exploitation · 2026-04-05: 71Active Exploitation · 2026-04-06: 115Active Exploitation · 2026-04-07: 55Active Exploitation · 2026-04-08: 8Active Exploitation · 2026-04-09: 4Active Exploitation · 2026-04-10: 10Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-12: 2Active Exploitation · 2026-04-13: 6Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-04-15: 7Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-04-20: 2Active Exploitation · 2026-04-21: 4Active Exploitation · 2026-04-22: 3Active Exploitation · 2026-04-23: 1Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-05-05: 1Active Exploitation · 2026-05-06: 5Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-09: 1Active Exploitation · 2026-05-12: 1Active Exploitation · 2026-05-13: 1Active Exploitation · 2026-05-15: 6Active Exploitation · 2026-05-21: 1Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-05-27: 3Active Exploitation · 2026-05-28: 23Active Exploitation · 2026-05-29: 14Active Exploitation · 2026-05-30: 3Active Exploitation · 2026-05-31: 1Active Exploitation · 2026-06-01: 2Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-06-04: 1Active Exploitation · 2026-06-05: 1Active Exploitation · 2026-06-08: 6Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-11: 2Active Exploitation · 2026-06-16: 1Active Exploitation · 2026-06-17: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-07-09: 1Active Exploitation · 2026-07-15: 1Patch / Workaround · 2026-04-04: 22Patch / Workaround · 2026-04-05: 49Patch / Workaround · 2026-04-06: 77Patch / Workaround · 2026-04-07: 36Patch / Workaround · 2026-04-08: 8Patch / Workaround · 2026-04-09: 3Patch / Workaround · 2026-04-10: 5Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-13: 7Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 8Patch / Workaround · 2026-04-18: 2Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-20: 3Patch / Workaround · 2026-04-21: 3Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-24: 3Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-06: 4Patch / Workaround · 2026-05-12: 2Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-28: 8Patch / Workaround · 2026-05-29: 4Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-06-06: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-09-10: 1Technical Details · 2026-04-04: 21Technical Details · 2026-04-05: 32Technical Details · 2026-04-06: 87Technical Details · 2026-04-07: 40Technical Details · 2026-04-08: 9Technical Details · 2026-04-09: 5Technical Details · 2026-04-10: 7Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 3Technical Details · 2026-04-13: 7Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 5Technical Details · 2026-04-18: 2Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 3Technical Details · 2026-04-21: 4Technical Details · 2026-04-22: 3Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 3Technical Details · 2026-04-25: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-06: 3Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 2Technical Details · 2026-05-13: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-28: 15Technical Details · 2026-05-29: 6Technical Details · 2026-05-30: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-16: 3Technical Details · 2026-06-17: 3Technical Details · 2026-06-25: 5Technical Details · 2026-07-09: 1Technical Details · 2026-07-15: 1Technical Details · 2026-08-27: 104-0404-1004-1804-2405-0105-1105-2706-0306-1106-3008-2709-10
Signal classification6 categories
Active Exploitation
35569.1%
Patch
7214.0%
Disclosure
418.0%
General
356.8%
PoC
101.9%
Exploit
10.2%
Referenced assets294 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-0434
Active Exploitation22Disclosure6General1Patch5
2026-04-0580
Active Exploitation59Disclosure1General5Patch14PoC1
2026-04-06126
Active Exploitation98Disclosure8General1Patch18PoC1
2026-04-0762
Active Exploitation50Disclosure5General2Patch5
2026-04-0813
Active Exploitation5Disclosure2General2Patch4
2026-04-097
Active Exploitation3Disclosure2Patch2
2026-04-1010
Active Exploitation9Patch1
2026-04-112
Disclosure1General1
2026-04-123
Active Exploitation2General1
2026-04-138
Active Exploitation6Patch2
2026-04-142
Active Exploitation1Patch1
2026-04-1511
Active Exploitation7General1Patch3
2026-04-182
Patch2
2026-04-191
Patch1
2026-04-205
Active Exploitation2Disclosure1Patch2
2026-04-216
Active Exploitation3General2Patch1
2026-04-224
Active Exploitation3Patch1
2026-04-231
Active Exploitation1
2026-04-243
Active Exploitation1Patch2
2026-04-251
PoC1
2026-04-272
Active Exploitation2
2026-04-281
Active Exploitation1
2026-04-291
Active Exploitation1
2026-04-301
Active Exploitation1
2026-05-011
General1
2026-05-041
Active Exploitation1
2026-05-051
Active Exploitation1
2026-05-067
Active Exploitation3Disclosure1Patch2PoC1
2026-05-072
Active Exploitation1PoC1
2026-05-095
Active Exploitation1PoC4
2026-05-111
PoC1
2026-05-122
Active Exploitation1Patch1
2026-05-131
Active Exploitation1
2026-05-156
Active Exploitation6
2026-05-213
Active Exploitation1General2
2026-05-222
Active Exploitation1Disclosure1
2026-05-273
Active Exploitation3
2026-05-2826
Active Exploitation23Disclosure3
2026-05-2917
Active Exploitation14General2Patch1
2026-05-305
Active Exploitation3Disclosure1General1
2026-05-311
Active Exploitation1
2026-06-014
Active Exploitation1Exploit1General2
2026-06-031
Active Exploitation1
2026-06-041
Active Exploitation1
2026-06-051
Active Exploitation1
2026-06-061
Patch1
2026-06-086
Active Exploitation6
2026-06-102
Active Exploitation1General1
2026-06-113
Active Exploitation2General1
2026-06-163
Active Exploitation1Disclosure2
2026-06-176
Active Exploitation1Disclosure2General3
2026-06-201
General1
2026-06-256
Active Exploitation1Disclosure4General1
2026-06-261
Disclosure1
2026-06-301
General1
2026-07-011
General1
2026-07-081
General1
2026-07-091
Patch1
2026-07-151
Active Exploitation1
2026-08-021
General1
2026-08-271
Patch1
2026-09-101
Patch1
Full discourse20 posts
  • Defused@DefusedCyber
    Active Exploitation

    🚨 New Fortinet vulnerability being exploited as an 0-day CVE-2026-35616 - FortiClient EMS pre-authentication API access bypass - CVSS 9.1 Critical After observing in-the-wild exploitation of this vulnerability earlier this week, Defused reported it to Fortinet under responsible disclosure. Fortinet has released an emergency hotfix - plus a scheduled patch - for FortiClient EMS 7.4.5 and 7.4.6. The vulnerability allows an unauthenticated attacker to bypass API authentication and authorization entirely, unauthorized code or commands via crafted requests. This discovery was made through our upcoming Radar feature launching next week 😇 Advisory: https://fortiguard.com/psirt/FG-IR-26-099 Track exploitation of this and other Fortinet vulns in real time and get updates on the new Defused Radar 👉 https://console.defusedcyber.com/signup Credit also to @heckintosh_ for independently discovering this vulnerability 💪

    Post summary

    CVE‑2026‑35616, a critical FortiClient EMS API authentication bypass, is actively exploited in the wild and has received an emergency hotfix and scheduled patch.

    111111435115077.1K
    7.3K followersView on X
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    ‼️🚨 Hacked Fortinet FortiClient EMS servers are pushing infostealer malware disguised as a Fortinet patch to every managed endpoint. Attackers exploit CVE-2026-35616 to take the server, then abuse FortiClient's own management channel to deploy it. Patch now! https://t.co/i3Wb7fEuRK

    Post summary

    The tweet warns that attackers are exploiting CVE‑2026‑35616 to compromise Fortinet FortiClient EMS servers and push infostealer malware, and urges users to apply the available patch immediately.

    867541012445.9K
    193.5K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-35616 PT ID: PT-2026-30288 Vendor: Fortinet Product: FortiClientEMS Description: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Link: https://github.com/Alaatk/CVE-2026-35616 #dbugs_vuln

    Post summary

    A publicly released PoC/enabling exploit for CVE-2026-35616 demonstrates an improper access control flaw in FortiClientEMS that permits unauthenticated remote code execution, but there is no evidence of active exploitation or patch availability yet.

    048124613619.1K
    2.3K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Fortinet is warning of active exploitation of CVE-2026-35616 (CVSS 9.1) in FortiClient EMS. The flaw lets unauthenticated attackers bypass API controls and run code. This is the second critical EMS flaw exploited in weeks. 🔗 Full details → https://thehackernews.com/2026/04/fortinet-patches-actively-exploited-cve.html

    Post summary

    Fortinet warns that CVE-2026-35616 is being actively exploited in FortiClient EMS, allowing unauthenticated code execution via API bypass, with no patch or PoC mentioned.

    79062714532.6K
    1.6M followersView on X
  • NullSecurityX@NullSecurityX
    PoC

    FortiClient Endpoint Management Server authentication bypass (CVE-2026-35616) A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands.. https://github.com/Alaatk/CVE-2026-35616 https://t.co/yAgk2PSSJb

    Post summary

    The text highlights an authentication bypass vulnerability (CVE‑2026‑35616) in FortiClientEMS and provides a GitHub link that likely contains a proof‑of‑concept exploit, with no indication of active exploitation or available patch.

    43301336610.0K
    12.3K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 CISA Warns of Fortinet 0-Day Vulnerability Actively Exploited in Attacks Source: https://cybersecuritynews.com/cisa-warns-fortinet-vulnerability/ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-35616, a critical improper access control vulnerability in Fortinet FortiClient Enterprise Management Server (EMS), to its Known Exploited Vulnerabilities (KEV) catalog on April 6, 2026, mandating federal agencies to remediate by April 9, 2026. CVE-2026-35616 is a critical-severity flaw rooted in CWE-284 (Improper Access Control), carrying a CVSS score of 9.1. The vulnerability specifically affects FortiClient EMS versions 7.4.5 and 7.4.6, while the 7.2 branch remains unaffected. The flaw functions as a pre-authentication API access bypass, enabling privilege escalation without any valid credentials. #cybersecuritynews

    Post summary

    CISA has flagged Fortinet CVE-2026-35616 as an actively exploited vulnerability, noting its critical severity and impact on FortiClient EMS, but no patch or workaround information is provided.

    44241473310.4K
    65.9K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 We are now observing further exploitation of the recent FortiClient zero-day (CVE-2026-35616) No public POC exists to date, and this exploit has roughly the same structure as the observed zero-day exploit. To identify potential compromise, defenders should look for traffic from unknown IPs with the X-SSL-CLIENT-VERIFY header set to SUCCESS The two exploiting IP addresses to date: 51.79.66.]183 94.253.208.]16 Monitor exploits against Fortinet Forticlient EMS 👉 https://console.defusedcyber.com/intel

    Post summary

    FortiClient CVE‑2026‑35616 is being actively exploited in the wild, with two IP addresses implicated and a distinctive traffic header used for detection; however, no public PoC, exploit code, patch, or false‑positive claim is provided.

    23211145727.2K
    7.3K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Threat actors are exploiting a critical FortiClient EMS flaw to push credential-stealing malware to entire networks of managed endpoints. CVE-2026-35616 (CVSS 9.1) allows pre-auth bypass and privilege escalation. Read full report: https://thehackernews.com/2026/05/threat-actors-exploit-critical.html

    Post summary

    Threat actors have discovered and are actively exploiting CVE‑2026‑35616 in FortiClient EMS to deploy credential‑stealing malware across managed endpoint networks.

    63141062329.5K
    1.9M followersView on X
  • Simo@SimoKohonen
    General

    CVE-2026-35616 has escaped the zero day orbit

    Post summary

    The brief statement indicates that CVE‑2026‑35616 is no longer treated as a zero‑day vulnerability, but no additional details on exploitation, mitigation, or technical aspects are provided.

    2150571814.8K
    3.2K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    Threat actors exploited CVE-2026-35616 to modify FortiClient EMS configurations and silently push EKZ Infostealer across all managed endpoints. The payload was disguised as a legitimate “FortiEndpoint_Patch.exe” and executed through a Base64-encoded PowerShell script. It steals browser credentials, cookies, autofill data — and can enable follow-on access that sometimes bypasses MFA. Patch to FortiClient EMS 7.4.7 or newer immediately. Unpatched EMS servers can turn into a malware distribution platform for entire networks.

    Post summary

    CVE‑2026‑35616 is being actively exploited to distribute EKZ Infostealer across FortiClient EMS endpoints; patching to version 7.4.7 or newer is urgently required.

    514162717.0K
    1.9M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Fortinet FortiClient EMS improper access control vulnerability CVE-2026-35616 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/uA0f8NRspV

    Post summary

    DHS highlights that CVE-2026-35616 in Fortinet FortiClient EMS is actively exploited, noting its inclusion in their Known Exploited Vulnerabilities Catalog.

    62204448.4K
    298.7K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ One Forged Header: Unauthenticated Authentication Bypass in Fortinet FortiClient EMS (CVE-2026-35616) https://darkwebinformer.com/one-forged-header-unauthenticated-authentication-bypass-in-fortinet-forticlient-ems-cve-2026-35616/

    Post summary

    The post references a disclosure of CVE-2026-35616, an unauthenticated authentication bypass in Fortinet FortiClient EMS, but provides no PoC, exploit code, or patch details.

    172471811.2K
    223.7K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    ⚠️ We are observing an actor targeting FortiClient EMS fabric integration endpoints using a novel twist to the attack technique from CVE-2026-35616. Unlike the original campaign which targeted admin API access, this actor is attempting to register rogue FortiGate devices into the EMS trust fabric - a higher-impact attack path. Organizations running FortiClient EMS should consider restricting network access to the management interface regardless of patch status. Based on testing it seems the hotfix / patch successfully blocks this attack. IOCs and details on Defused Radar 👉 http://console.defusedcyber.com/radar

    Post summary

    Defused Cyber reports an active threat actor exploiting CVE‑2026‑35616 via rogue FortiGate registration into the FortiClient EMS trust fabric, and a hotfix/patch that blocks the attack has been confirmed.

    41514697.0K
    7.4K followersView on X
  • Cristian Borghello@SeguInfo
    General

    Como diría alguien (de #Fortinet): "que MAL que la estoy pasando"😤 - CVE-2026-21643 - Inyección SQL (9.1) - CVE-2026-35616 - Control de acceso inadecuado (9.1) - CVE-2026-39808 - Ejecución de comandos (9.1) 🔗https://blog.segu-info.com.ar/2026/04/otra-vulnerabilidad-critica-rce-en.html PARCHEA!

    Post summary

    The post lists three high‑severity CVEs and urges patching, but offers no exploit details, PoC or vendor mitigation specifics.

    012038152.9K
    38.3K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    Heads up FortiClient EMS users! CVE-2026-35616 (new) & CVE-2026-21643 - both unauthenticated RCE observed to be exploited in the wild! We fingerprint about 2000 instances globally, see public Dashboard: https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=30&vendor=fortinet&model=forticlient+enterprise+management+server+%28ems%29&dataset=count&limit=100&group_by=geo&stacking=stacked&auto_update=on Top affected: US & Germany https://dashboard.shadowserver.org/statistics/iot-devices/map/?date_range=1&vendor=fortinet&model=forticlient+enterprise+management+server+%28ems%29&data_set=count&scale=log&auto_update=on https://t.co/tLOs6mhgBk

    Post summary

    The post warns FortiClient EMS users that CVE-2026-35616 and CVE-2026-21643 are currently being exploited worldwide, providing a dashboard link for affected distributions but offering no patches or PoC details.

    114133158.5K
    21.8K followersView on X
  • Simo@SimoKohonen
    General

    Many asking about POC / IOCs for CVE-2026-35616 (the FortiClient 0-day) Outside of informing @defused customer base who deal with detection engineering, I haven't released much info about it It's really really easy to exploit and I'm entirely sure a good bunch of Fortinet admins haven't patched given its the weekend plus a major holiday Also haven't seen further exploitation in our honeypots thus far. Quite sure someone will reverse it soon but if not and / or more exploits start happening will publish details early into the week to give people a plausible chance to patch it

    Post summary

    The post references FortiClient CVE‑2026‑35616, states no evidence of exploitation yet, and plans to release more detail if needed, but offers no actionable information.

    34044117.4K
    3.2K followersView on X
  • Censys@censysio
    Active Exploitation

    🚨 Critical vulnerability: CVE-2026-35616 is an improper access control vulnerability affecting Fortinet FortiClient EMS (CVSS v3.1 9.1). Allows unauthorized code & command execution from remote unauthenticated attackers. ⚠️ Actively exploited in the wild 🛠️ Hotfix available If you are running these devices, treat your Internet-exposed EMS management surfaces as high risk until patched and consider restricting access to trusted networks where possible. 🔗 Learn more in the full advisory: https://hubs.ly/Q049SVt30 #CensysARC #CVE202635616

    Post summary

    CVE-2026-35616 is an improperly controlled access flaw in Fortinet FortiClient EMS, actively exploited in the wild, with a hotfix already released. Users are advised to patch promptly or restrict network access.

    011025133.0K
    12.4K followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    CVE-2026-35616 is now on VulnCheck KEV ✅

    Post summary

    CVE-2026-35616 has been added to VulnCheck KEV, signifying it is actively exploited in the wild.

    1813098.1K
    3.6K followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - Alaatk/CVE-2026-35616: Fortinet FortiClientEMS improper access control · GitHub https://github.com/Alaatk/CVE-2026-35616

    Post summary

    A public GitHub repository (Alaatk/CVE-2026-35616) appears to host proof‑of‑concept exploit code for Fortinet FortiClientEMS improper access control, but no evidence of live exploitation or remediation is presented.

    14032103.7K
    62.1K followersView on X
  • Dmitry Melikov@DmitriyMelikov
    Active Exploitation

    Unattributed TA use CVE-2026-35616 in FortiClient EMS to deploy #EKZInfostealer Details, #iocs, and Rules are inside. ⬇️ https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/ #Infostealer #cybersecurity @AWNetworks https://t.co/UhuwD50pV3

    Post summary

    The post reports that threat actors have actively exploited CVE-2026-35616 in FortiClient EMS to deliver the EKZ Infostealer, with a link to documentation containing IOCs and deployment rules.

    09027102.8K
    2.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetforticlientems7.4.5--
Appfortinetforticlientems7.4.6--

Explore more