Fortinet FortiClientEMS Vulnerability Could Allow for Arbitrary Code Execution (CVE-2026-35616)
- •Fortinet FortiClientEMS versions 7.4.5 through 7.4.6
Executive Summary
MS-ISAC Advisory 2026-031 (issued 4/4/2026): an improper access control vulnerability in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6 allows unauthenticated attackers to execute unauthorized code or commands via crafted network requests, which could allow for arbitrary code execution in the context of the affected service account. Fortinet has observed this vulnerability being exploited in the wild.
Municipal Impact
MS-ISAC rates the risk as Medium for large, medium, and small government entities; municipal organizations using FortiClientEMS should apply available hotfixes promptly.
SMB Impact
MS-ISAC rates the risk as Medium for large, medium, and small business entities; not applicable to home users.
Recommended Actions
- Apply available hotfixes provided by Fortinet to vulnerable systems immediately after appropriate testing.
- Apply additional updates (7.4.7 or above) when they become available.
- Follow CIS Safeguards for vulnerability management, automated vulnerability scanning, and remediation.
Grey Matter Analysis
References
- https://learn.cisecurity.org/e/799323/CVERecord-id-CVE-2026-35616/4vvb84/2666782263/h/jVoMVgdjSKQCe0RClvoef61OARO3e4O6FHskLZmiS-k
- https://learn.cisecurity.org/e/799323/psirt-FG-IR-26-099/4vvb81/2666782263/h/jVoMVgdjSKQCe0RClvoef61OARO3e4O6FHskLZmiS-k
- https://learn.cisecurity.org/e/799323/resources--type-advisory/4vvb7x/2666782263/h/jVoMVgdjSKQCe0RClvoef61OARO3e4O6FHskLZmiS-k
Tags
Related Intelligence
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter