CVE-2026-35616
This weakness allows attackers to conduct the following: Delivery - The attacker sends a crafted HTTP/API request targeting the vulnerable FortiClient EMS instance, reaching the unauthenticated API interface exposed on the network. Improper Access Control - FortiClient EMS fails to enforce proper authentication and authorization on specific API endpoints, allowing the crafted request to bypass access controls. Execution / Post‑Compromise - The crafted request results in execution of unauthorized code or commands on the EMS server, enabling the attacker to obtain control of administrative functionality. Post‑Compromise Impact - Attackers who successfully exploit this flaw can manipulate or exfiltrate sensitive configuration and policy data, corrupt or disable endpoint protections, disrupt endpoint management services, deploy malicious payloads, and use the compromised EMS as a foothold for further network intrusion or lateral movement.
EPSS 34.75% · 97.1th percentile
Risk Scores
Timeline
- Apr 4, 2026 EPSS Score
- Apr 4, 2026 CVE Published
- Apr 4, 2026 PoC Published
- Apr 4, 2026 PoC Published
- Apr 4, 2026 PoC Published
- Apr 4, 2026 PoC Published
- Apr 4, 2026 PoC Published
- Apr 4, 2026 Security Advisory
- Apr 6, 2026 CISA KEV Added
- Apr 7, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-critical-cve-2026-35616-actively-exploited-allowing-attackers-gain-unauthorized advisory
- https://fortiguard.fortinet.com/psirt/FG-IR-26-099 vendor
- https://nvd.nist.gov/vuln/detail/CVE-2026-35616 technical
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35616 advisory