CVE-2026-35616

FortiClientEMS vulnerability analysis and mitigation CRITICAL (CVSS 9.8)

Overview

An improper access control vulnerability in FortiClientEMS could enable an unauthenticated remote actor to execute arbitrary code or commands via crafted requests. The flaw has been publicly exploited and multiple proofs-of-concept are available.

CISA added CVE-2026-35616 to the Known Exploited Vulnerabilities catalog on April 6, 2026, confirming exploitation in the wild. Its use in ransomware campaigns is unknown.

Technical details

The vulnerability arises from insufficient restrictions on a network-accessible endpoint within the server. Because access control is not properly enforced, an unauthenticated attacker transmitting a crafted request can bypass all guardrails and execute arbitrary code or commands, achieving the highest levels of system impact.

Root cause

The vulnerability is caused by an improper access control mechanism, which allows unrestricted network access to sensitive functionality without requiring authentication.

Weakness classification

  • CWE-284 — Improper Access Control

Base Score

This vulnerability has a CVSS v3.1 base score of 9.8 (CRITICAL)with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C.

Impact

A vulnerability originating from improper access control allows an unauthenticated attacker to execute unauthorized code or commands through specially crafted requests. This leads to a full compromise of confidentiality, integrity, and availability with no user interaction or elevated privileges required.

Mitigation and workarounds

Fixed version

No fixed version has been published in the source feeds. Check the vendor advisory for remediation guidance.

Recommended action

  • Vullify: Patch immediately (24-48 hours) - P0 priority.
  • CISA: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal agencies must remediate by April 9, 2026.

References

Where this data comes from

The classification, scoring, affected versions, dates and links on this page are rendered directly from these sources:

Source record last changed on April 4, 2026.

Narrative sections are machine-generated and cross-checked against the sources above; anything they assert that those sources do not support is withheld. Last generated July 29, 2026.

Related FortiClientEMS Vulnerabilities

No related vulnerabilities found with identified affected products.