Fortinet logo on shield and patch

Fortinet Warns of Active Server Attacks

Fortinet issued emergency hotfixes for a critical vulnerability in FortiClient EMS that allows remote code execution.

Fortinet has released emergency out-of-band hotfixes to address a critical vulnerability in its FortiClient Endpoint Management Server (EMS), tracked as CVE-2026-35616. The flaw, has a CVSS score of 9.8, is currently being exploited in the wild and grants an unauthenticated attacker full control over managed workstations and laptops, according a bulletin issued by FortiGuard Labs on Saturday.

The company warned, “Fortinet has observed this to be exploited in the wild.”

The company has released a hotfix to mitigate the bug (PDF). A permanent patch will be available in the upcoming version 7.4.7. Meanwhile, versions which have not received the hotfix – 7.4.5 through 7.4.6 – are vulnerable to attack.  

Shadowserver Foundation on Sunday posted on X that nearly 2,000 FortiClient EMS instances remain internet-exposed and vulnerable to CVE-2026-35616 and another previously patched flaw CVE-2026-21643, reported in February.

“Heads up FortiClient EMS users! CVE-2026-35616 (new) & CVE-2026-21643 – both unauthenticated RCE observed to be exploited in the wild! We fingerprint about 2000 instances globally,” it wrote.

Fortinet says the new flaw (CVE-2026-35616) allows a remote, unauthenticated attacker to execute unauthorized code or commands through crafted requests to the EMS API. Attackers can bypass the authentication and authorization checks that are supposed to protect the management server, researchers noted.

The EMS API is the application programming interface used by the management server for administrative and configuration operations. The FortiClient software handles endpoint registrations, and managing security settings across Windows, macOS, Linux, Android, iOS, and ChromeOS devices.

On Saturday Defused, credited for first identifying the attacks, wrote in a LinkedIn post that it observed in-the-wild exploitation earlier in the week and reported the vulnerability to Fortinet.

Fortinet says the hotfix, issued over the weekend, is sufficient to prevent this bug entirely, while the upcoming 7.4.7 release will include the permanent fix as part of the normal code line. Fortinet has not published a date for 7.4.7.

This is the second serious FortiClient EMS issued recently. The previous bug, CVE-2026-21643, was a SQL injection flaw in FortiClient EMS 7.4.4. Fortinet published that advisory on Feb. 6, 2026, said it was already being exploited in the wild, and told customers to upgrade to 7.4.5 or later. Bishop Fox later noted that CVE-2026-21643 was effectively a single-version bug introduced in 7.4.4 and patched one release later in 7.4.5.

Direct Mitigation and Recovery Recommendations

According to Fortinet’s PSIRT advisory affected customers should immediately install the emergency hotfixes for EMS 7.4.5 and 7.4.6. Fortinet’s release notes (PDF) identify the patched builds as 7.4.5.2111.1277073 and 7.4.6.2170.1277073. Fortinet also recommends restricting management and API access so the EMS interface is not exposed to the open internet.

Total
0
Shares
Previous Article
Lego office worker is arrested

NJ Engineer Admits to $750,000 Extortion Plot

Next Article
apple logo grey

Mac Malware Goes Credential Hunting

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading