Fortinet EMS Zero-Day CVE-2026-35616 Confirmed — Apply Hotfix Now

TL;DR AI
2 min readKey summary
Fortinet confirmed a pre-authentication API access bypass in FortiClientEMS that allows unauthorized code execution.
The vulnerability CVE-2026-35616 has a CVSS score of 9.1 and is being actively exploited in the wild.
Fortinet released an emergency hotfix for FortiClientEMS 7.4.5 and 7.4.6 and said version 7.4.7 will contain a permanent fix.



