Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA KEV listing and FCEB patch order for CVE-2026-35616

Public Sector Action
First reported
Last updated
Happening score
H score 53
1 unique sources, 1 articles

Summary

Hide ▲

CISA added CVE-2026-35616 to the KEV Catalog and ordered FCEB agencies to patch FortiClient EMS by Thursday midnight, April 9. The mandate matters because the flaw is already exploited in the wild and can let attackers bypass authentication and authorization controls. CISA tied the order to BOD 22-01, making the remediation deadline compulsory for the affected federal systems.

Related Happenings

CISA BOD 26-04 SharePoint remediation deadline

Public Sector Action
H score77 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...

CISA KEV directive for Joomla extension flaws

Public Sector Action
H score36 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...

CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server

Public Sector Action
H score35 First: 26.06.2026 22:43 Last: 26.06.2026 22:43 Sources 1

About this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...

CISA BOD 26-04 three-day remediation directive

Public Sector Action
H score36 First: 24.06.2026 17:35 Last: 24.06.2026 17:35 Sources 1

About this happening: CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...

Timeline

  1. 06.04.2026 19:02 2 articles · 3mo ago

    CISA adds CVE-2026-35616 to KEV and orders FCEB patching

    Legal Policy Action Update

    CISA added CVE-2026-35616 to the Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to patch FortiClient EMS instances by Thursday midnight, April 9, under Binding Operational Directive (BOD) 22-01.

    Show sources
  2. 06.04.2026 19:02 1 articles · 3mo ago

    Defused identifies CVE-2026-35616 in FortiClient EMS as a pre-auth access bypass

    Technical Analysis Update

    Defused identified CVE-2026-35616 as a pre-authentication API access bypass in FortiClient Enterprise Management Server (EMS) that can let attackers bypass authentication and authorization controls entirely; Fortinet released emergency hotfixes for FortiClient EMS 7.4.5 and 7.4.6, said unauthenticated attackers can execute code or commands via specially crafted requests, and Shadowserver tracked nearly 2,000 exposed instances with more than 1,400 IPs in the United States and Europe.

    Show sources