FortiClient EMS CVE-2026-35616 exploitation and stealer delivery
Case score 56
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 56
- Main story score
- 56
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 1
- Exploitation Wave Observed exploitation of CVE-2026-35616 to push malware through EMS-managed channels. main
- Vulnerability Adds fix availability, KEV status, and reported internet exposure for the same CVE-2026-35616 in FortiClient EMS. context
Overview
Latest development Open development history Fortinet confirms CVE-2026-35616 active exploitation Fortinet confirms that CVE-2026-35616 is actively exploited in the wild, credits Defused with finding a pre-authentication API access bypass in FortiClient EMS, and notes that Shadowserver found more than 2,000 exposed EMS instances online, mostly in the USA and Germany. Defused says the flaw was observed as a zero-day earlier this week before responsible disclosure to Fortinet.
-
FortiClient EMS CVE-2026-35616 exploitation wave
By **May 2026**, attackers were using a patched **FortiClient EMS** flaw to push malicious scripts through the product's management path. The early phase centered on abusing EMS controls to reach every managed endpoint from a privileged context.
-
FortiClient EMS pre-auth API access bypass (CVE-2026-35616)
Attackers were already abusing **CVE-2026-35616** against **FortiClient EMS** in **May 2026**. The flaw provided **pre-auth API access bypass** and **privilege escalation** before remediation in **7.4.7 and later**.
-
Fortinet issues emergency hotfix for CVE-2026-35616
Fortinet releases an emergency hotfix for CVE-2026-35616, an improper access control flaw in FortiClient EMS 7.4.5 and 7.4.6 that can let unauthenticated attackers execute code or commands via specially crafted requests. Fortinet says FortiClient EMS 7.4.7 will also fix the issue and urges customers to install the hotfix immediately.