Overview
An improper access control vulnerability in FortiClientEMS could enable an unauthenticated remote actor to execute arbitrary code or commands via crafted requests. The flaw has been publicly exploited and multiple proofs-of-concept are available.
CISA added CVE-2026-35616 to the Known Exploited Vulnerabilities catalog on April 6, 2026, confirming exploitation in the wild. Its use in ransomware campaigns is unknown.
Technical details
The vulnerability arises from insufficient restrictions on a network-accessible endpoint within the server. Because access control is not properly enforced, an unauthenticated attacker transmitting a crafted request can bypass all guardrails and execute arbitrary code or commands, achieving the highest levels of system impact.
Root cause
The vulnerability is caused by an improper access control mechanism, which allows unrestricted network access to sensitive functionality without requiring authentication.
Weakness classification
- CWE-284 — Improper Access Control
Base Score
This vulnerability has a CVSS v3.1 base score of 9.8 (CRITICAL)with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C.
Impact
A vulnerability originating from improper access control allows an unauthenticated attacker to execute unauthorized code or commands through specially crafted requests. This leads to a full compromise of confidentiality, integrity, and availability with no user interaction or elevated privileges required.
Mitigation and workarounds
Fixed version
No fixed version has been published in the source feeds. Check the vendor advisory for remediation guidance.
Vendor Advisory
Recommended action
- Vullify: Patch immediately (24-48 hours) - P0 priority.
- CISA: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal agencies must remediate by April 9, 2026.
References
- fortiguard.fortinet.com — Patch, Vendor Advisory
- www.cisa.gov — US Government Resource
Where this data comes from
The classification, scoring, affected versions, dates and links on this page are rendered directly from these sources:
- CIRCL — Computer Incident Response Center Luxembourg
- CISA — Known Exploited Vulnerabilities catalog
- FIRST — Exploit Prediction Scoring System (EPSS)
- Public exploit and proof-of-concept evidence
- NVD — National Vulnerability Database
- CVE.org — CVE Program record
- Vendor security advisory
Source record last changed on April 4, 2026.
Additional sources consulted
Narrative sections are machine-generated and cross-checked against the sources above; anything they assert that those sources do not support is withheld. Last generated July 29, 2026.
