CISA Mandates Urgent Fortinet Fix
CriticalExecutive Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a critical, actively exploited vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS).
Tracked as CVE-2026-35616, this improper access control flaw allows unauthenticated attackers to bypass authentication and achieve remote code execution.
Vulnerability Details
- Affected Product:FortiClient EMS versions 7.4.5 through 7.4.6
- Identifier: CVE-2026-35616
- CVSS Score: 9.1 (Critical)
- Exploitation Status:Actively Exploited (in the wild since late March 2026)
Risk & Impact
- Triage: Immediate patching is required. CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on April 6, 2026.
- Attack Vector: An unauthenticated attacker can send specially crafted requests to bypass API access controls, leading to privilege escalation and remote code execution.
- Ease of Exploit: Exploitation has been observed in real attacks; Fortinet released an emergency hotfix.
Action Plan
- Immediate Action: Install the emergency hotfix for FortiClient EMS 7.4.5/7.4.6 or upgrade to 7.4.7 (or later). Federal agencies must remediate by April 9, 2026.
- Workaround: Restrict administrative interface access from the internet and block unnecessary exposure of EMS instances.
- Detection: Monitor for anomalous API calls to FortiClient EMS, unauthorized privilege escalation, and suspicious remote management activity.
Relevant professional terms
- Improper Access Control
- A vulnerability where an application fails to properly enforce authorization, allowing attackers to access restricted functionality or data.
- Known Exploited Vulnerabilities (KEV) Catalog
- A list maintained by CISA that contains vulnerabilities known to be actively exploited by malicious actors. Federal agencies are required to remediate vulnerabilities in the KEV catalog by a specified due date.
Source: BleepingComputer
