VDB

CVE-2026-35616

CVE-2026-35616 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

This weakness allows attackers to conduct the following: Delivery - The attacker sends a crafted HTTP/API request targeting the vulnerable FortiClient EMS instance, reaching the unauthenticated API interface exposed on the network. Improper Access Control - FortiClient EMS fails to enforce proper authentication and authorization on specific API endpoints, allowing the crafted request to bypass access controls. Execution / Post‑Compromise - The crafted request results in execution of unauthorized code or commands on the EMS server, enabling the attacker to obtain control of administrative functionality. Post‑Compromise Impact - Attackers who successfully exploit this flaw can manipulate or exfiltrate sensitive configuration and policy data, corrupt or disable endpoint protections, disrupt endpoint management services, deploy malicious payloads, and use the compromised EMS as a foothold for further network intrusion or lateral movement.

EPSS 34.75% · 97.1th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
34.75%
97.1th percentile

Timeline

  • Apr 4, 2026 EPSS Score
  • Apr 4, 2026 CVE Published
  • Apr 4, 2026 PoC Published
  • Apr 4, 2026 PoC Published
  • Apr 4, 2026 PoC Published
  • Apr 4, 2026 PoC Published
  • Apr 4, 2026 PoC Published
  • Apr 4, 2026 Security Advisory
  • Apr 6, 2026 CISA KEV Added
  • Apr 7, 2026 Security Advisory
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›