radar

ONE Sentinel

securitySecurity/THREATS/CRIT

New FortiClient EMS flaw exploited in attacks, emergency patch released

sourceBleeping Computer
calendar_todayApril 5, 2026
schedule1 min read
lightbulb

EXECUTIVE SUMMARY

Critical FortiClient EMS Vulnerability Exploited, Emergency Patch Released

Summary

Fortinet has issued an emergency security update to address a critical vulnerability in FortiClient Enterprise Management Server (EMS) that is currently being actively exploited in attacks.

Key Points

  • Fortinet released an emergency patch over the weekend for FortiClient EMS.
  • The vulnerability is identified as CVE-2026-35616.
  • This flaw is classified as critical due to active exploitation in the wild.
  • The update aims to mitigate the risk posed by the vulnerability.

Analysis

The release of an emergency patch by Fortinet highlights the severity of the vulnerability in FortiClient EMS. The active exploitation of CVE-2026-35616 poses a significant threat to organizations using this product, emphasizing the need for immediate action to protect systems from potential breaches.

Conclusion

IT professionals should prioritize applying the emergency patch for FortiClient EMS to safeguard against the critical vulnerability CVE-2026-35616. Regularly updating and monitoring systems for security patches is essential to mitigate risks from such exploits.