Signal

Critical FortiClient EMS zero-day exploited in the wild, emergency patches released

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-04-04 13:49 UTCUpdated 2026-04-04 14:09 UTC
rss
cveexploitssecurity_advisoriesincident_response
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
limited source diversity in top sources
Overview

A critical zero-day vulnerability (CVE-2026-35616) in Fortinet's FortiClient Endpoint Management Server (EMS) has been actively exploited. The flaw involves improper access control allowing unauthenticated attackers to bypass security checks and execute unauthorized code remotely.

Entities
FortinetFortiClient EMS
Score total
0.98
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • Fortinet has confirmed active exploitation in the wild, signaling immediate threat.
  • Emergency hotfixes have just been released for affected FortiClient EMS versions.
  • Security authorities warn of imminent public proof-of-concept exploits increasing attack likelihood.
Why it matters
  • The vulnerability allows unauthenticated remote code execution, posing severe risk to affected systems.
  • Active exploitation increases urgency for organizations to patch immediately to prevent breaches.
  • Expected public exploits could lead to widespread scanning and attacks if unpatched.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • CVE-2026-35616 is a critical zero-day vulnerability in FortiClient EMS allowing unauthenticated remote code execution.
  • The vulnerability is actively exploited in the wild, with Fortinet urging immediate patching.
How sources frame it
  • Fortinet: neutral
  • NCSC NL Security Advisories: neutral
All evidence
All evidence
FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)
Help Net Security · helpnetsecurity.com · 2026-04-04 14:09 UTC
NCSC-2026-0107 [1.00] [H/H] Kwetsbaarheid verholpen in FortiClient EMS van Fortinet
NCSC NL Security Advisories · advisories.ncsc.nl · 2026-04-04 13:49 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • Help Net Security (1)
  • NCSC NL Security Advisories (1)
Top origin domains (this list)
  • helpnetsecurity.com (1)
  • advisories.ncsc.nl (1)