Critical FortiClient EMS flaw exploited before the advisory landed
Fortinet has published an advisory for CVE-2026-35616, a CVSS 9.8 unauthenticated remote code execution vulnerability in FortiClient EMS versions 7.4.5 and 7.4.6. The flaw was first discovered by the security company Defused and had already been observed exploited in the wild before Fortinet's advisory was published. Alongside the advisory, Fortinet has released a hotfix for both affected versions. The fix will be included in the upcoming 7.4.7 release, but Fortinet recommends installing the available hotfix immediately.
What this means for your organisation
FortiClient EMS is the system that manages your endpoints. An attacker who achieves code execution there is not standing on one machine but on the point that can reach all of them. Requiring no authentication removes the last obstacle. What makes this case particularly pressing is the sequence: the attacks preceded the advisory, so the usual assumption that you have a few days after publication does not hold.
Berigo recommends
- Install Fortinet's hotfix now if you run 7.4.5 or 7.4.6. Do not wait for 7.4.7.
- Check whether the EMS interface is reachable from the internet, and restrict access to what is strictly necessary.
- Review logs going backwards for signs of exploitation, since attacks began before the advisory.
- Ask your managed service provider to confirm in writing which version you actually run, and when the hotfix was applied.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch