CVE-2026-35616
CVE-2026-35616: 1 tracked advisory record across Fortinet. CISA KEV listed; exploitation observed. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Fortinet
1 advisory- Advisory severityCritical9.1
Critical [CVE-2026-35616] API authentication and authorization bypass
FG-IR-26-099Source published Source updated
CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6, by following the instructions at: - for FortiClientEMS 7.4.5https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484 - for FortiClientEMS 7.4.6Upcoming FortiClientEMS 7.4.7 will also include a fix for this issue. In the meantime the hotfix above is sufficient to prevent it entirely. Revised on 2026-04-04 00:00:00
- Related products — impact not confirmed
- FortiClient
- Source-reported affected versions
- 7.4.5
- 7.4.6
- 7.4.7
- Source-reported fixed versions
- FortiClientEMS 7.4: 7.4.7
- Mitigation guidance
- Upgrade per the Affected/Solution table: FortiClientEMS 7.4: 7.4.7.
Android app · Google Play
Monitor future Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.