Skip to content
VulniPulse
Highest advisory severityCritical Exploited CISA KEV 1 vendor · 1 advisory

CVE-2026-35616

CVE-2026-35616: 1 tracked advisory record across Fortinet. CISA KEV listed; exploitation observed. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Fortinet

1 advisory
  • Advisory severityCritical9.1

    Critical [CVE-2026-35616] API authentication and authorization bypass

    FG-IR-26-099Source published Source updated

    CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6, by following the instructions at: - for FortiClientEMS 7.4.5https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484 - for FortiClientEMS 7.4.6Upcoming FortiClientEMS 7.4.7 will also include a fix for this issue. In the meantime the hotfix above is sufficient to prevent it entirely. Revised on 2026-04-04 00:00:00

    Related products — impact not confirmed
    • FortiClient
    Source-reported affected versions
    • 7.4.5
    • 7.4.6
    • 7.4.7
    Source-reported fixed versions
    • FortiClientEMS 7.4: 7.4.7
    Mitigation guidance
    • Upgrade per the Affected/Solution table: FortiClientEMS 7.4: 7.4.7.

Android app · Google Play

Monitor future Fortinet CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery