VORANT. Threat Intelligence Sign in Get the full feed

Fortinet FortiClientEMS RCE exploited in wild

high vulnerability government-national

An unauthenticated remote code execution flaw in Fortinet FortiClientEMS is being actively exploited, affecting versions 7.4.5-7.4.6.

Fortinet FortiClientEMS, a centralized endpoint management platform, contains an improper access control vulnerability (CVE-2026-35616) that allows unauthenticated attackers to execute arbitrary code via crafted network requests. The flaw affects versions 7.4.5 through 7.4.6 and is exploited via public-facing application exposure, mapping to MITRE ATT&CK T1190. Fortinet has confirmed active exploitation in the wild, and the vulnerability requires no authentication, making internet-exposed EMS instances particularly at risk.

Successful exploitation grants code execution in the context of the FortiClientEMS service account, which could enable installation of malware, data manipulation or destruction, and creation of new privileged accounts depending on the service account's configured privileges. Organizations running least-privileged service accounts face reduced impact compared to those running with administrative rights. CISA/MS-ISAC recommend immediate application of Fortinet hotfixes, upgrading to 7.4.7 or later when available, applying least-privilege principles to service accounts, and standard vulnerability management practices including patch management, scanning, and network segmentation for exposed management interfaces.

Mentioned in this report

Vulnerabilities CVE-2026-35616KEV

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-fortinet-forticlientemscould-allow-for-arbitrary-code-execution_2026-031

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free