← Intelligence Center

Fortinet FortiClientEMS Vulnerability Could Allow for Arbitrary Code Execution (CVE-2026-35616)

PublishedApr 4, 2026
Updated
VendorFortinet
SeverityMedium
Known ExploitedYes Known Exploited
Advisory IDINTEL-000014
CVEs
CVE-2026-35616
Products
  • Fortinet FortiClientEMS versions 7.4.5 through 7.4.6

Executive Summary

MS-ISAC Advisory 2026-031 (issued 4/4/2026): an improper access control vulnerability in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6 allows unauthenticated attackers to execute unauthorized code or commands via crafted network requests, which could allow for arbitrary code execution in the context of the affected service account. Fortinet has observed this vulnerability being exploited in the wild.

Municipal Impact

MS-ISAC rates the risk as Medium for large, medium, and small government entities; municipal organizations using FortiClientEMS should apply available hotfixes promptly.

SMB Impact

MS-ISAC rates the risk as Medium for large, medium, and small business entities; not applicable to home users.

Recommended Actions

  1. Apply available hotfixes provided by Fortinet to vulnerable systems immediately after appropriate testing.
  2. Apply additional updates (7.4.7 or above) when they become available.
  3. Follow CIS Safeguards for vulnerability management, automated vulnerability scanning, and remediation.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter