# Fortinet FortiClientEMS RCE exploited in wild

Published: 2026-04-04 · Severity: high · Sectors: government-national
Canonical: https://vorant.io/reports/d8630e5f-c007-5611-97ec-34b55a3e4608/fortinet-forticlientems-rce-exploited-in-wild

> An unauthenticated remote code execution flaw in Fortinet FortiClientEMS is being actively exploited, affecting versions 7.4.5-7.4.6.

Fortinet FortiClientEMS, a centralized endpoint management platform, contains an improper access control vulnerability (CVE-2026-35616) that allows unauthenticated attackers to execute arbitrary code via crafted network requests. The flaw affects versions 7.4.5 through 7.4.6 and is exploited via public-facing application exposure, mapping to MITRE ATT&CK T1190. Fortinet has confirmed active exploitation in the wild, and the vulnerability requires no authentication, making internet-exposed EMS instances particularly at risk.

Successful exploitation grants code execution in the context of the FortiClientEMS service account, which could enable installation of malware, data manipulation or destruction, and creation of new privileged accounts depending on the service account's configured privileges. Organizations running least-privileged service accounts face reduced impact compared to those running with administrative rights. CISA/MS-ISAC recommend immediate application of Fortinet hotfixes, upgrading to 7.4.7 or later when available, applying least-privilege principles to service accounts, and standard vulnerability management practices including patch management, scanning, and network segmentation for exposed management interfaces.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35616 (KEV)

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-fortinet-forticlientemscould-allow-for-arbitrary-code-execution_2026-031

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d8630e5f-c007-5611-97ec-34b55a3e4608/fortinet-forticlientems-rce-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
