Vulnerabilities

CVE-2026-35616

Fortinet FortiClient EMS Improper Access Control Vulnerability

Actively exploited (CISA KEV) Critical 9.8 CVSS 3.1

Description

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Description as published by the source, in English.

Key facts

Published
2026-04-04
Last modified
2026-07-24
Assigned by
psirt@fortinet.com
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored by
psirt@fortinet.com
Probability of exploitation
88.9 % among the highest of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15
Fix available
Yes, see references

Actively exploited

CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-04-06, with a remediation deadline of 2026-04-09 for US federal agencies.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected products

Vendor Product Versions Status
Fortinet Forticlientems 7.4.5 Affected
Fortinet Forticlientems 7.4.6 Affected

Weakness type

Attack techniques

Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.

  • T1014: Rootkit stealth
  • T1027.009: Embedded Payloads stealth
  • T1037: Boot or Logon Initialization Scripts persistence, privilege-escalation
  • T1080: Taint Shared Content lateral-movement
  • T1505.005: Terminal Services DLL persistence
  • T1542.003: Bootkit stealth, persistence
  • T1543: Create or Modify System Process persistence, privilege-escalation
  • T1543.001: Launch Agent persistence, privilege-escalation
  • T1543.003: Windows Service persistence, privilege-escalation
  • T1543.004: Launch Daemon persistence, privilege-escalation
  • T1546.001: Change Default File Association privilege-escalation, persistence
  • T1546.004: Unix Shell Configuration Modification privilege-escalation, persistence
  • T1546.008: Accessibility Features privilege-escalation, persistence
  • T1546.016: Installer Packages privilege-escalation, persistence
  • T1547: Boot or Logon Autostart Execution persistence, privilege-escalation
  • T1547.006: Kernel Modules and Extensions persistence, privilege-escalation
  • T1553.004: Install Root Certificate defense-impairment
  • T1556.006: Multi-Factor Authentication defense-impairment, persistence, credential-access
  • T1574.011: Services Registry Permissions Weakness stealth, execution

References

Related at Berigo

Articles

Does this affect you?

A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.

Check your asset list Browse all vulnerabilities