
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35616 is a critical improper access control vulnerability (CWE-284) in Fortinet FortiClient EMS versions 7.4.5 through 7.4.6 that allows unauthenticated remote attackers to execute arbitrary code or commands via crafted API requests. The vulnerability was disclosed on April 4, 2026, and was exploited in the wild as a zero-day before the official patch was released. It carries a CVSS v3.1 base score of 9.8 (Critical) per the GitHub Advisory and NVD, while Fortinet's own advisory assigns a score of 9.1 (Critical) (Fortinet PSIRT, GitHub Advisory). CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on April 6, 2026, with a remediation due date of April 9, 2026 (CISA KEV).
The root cause is improper access control (CWE-284) in the FortiClient EMS API layer, where authentication and authorization checks can be bypassed via a crafted HTTP request — specifically through manipulation of a single HTTP header that tricks the server into treating an unauthenticated request as authorized (Fortinet PSIRT, Dark Web Informer). The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity, making it trivially exploitable by unauthenticated remote attackers. Bishop Fox published a technical analysis describing the flaw as an API authentication bypass in FortiClient EMS 7.4.5–7.4.6, and a Medium write-up titled "One HTTP Header to Rule Them All" detailed the specific header manipulation technique (Bishop Fox). Detection templates (Nuclei YAML) and Python-based checker scripts were published publicly, and multiple PoC repositories appeared on GitHub shortly after disclosure (GitHub PoC).
Successful exploitation grants an unauthenticated remote attacker the ability to execute arbitrary code or commands on the FortiClient EMS server, resulting in full system compromise with high impact to confidentiality, integrity, and availability. Because FortiClient EMS is an enterprise endpoint management platform that manages endpoint security policies and client configurations across an organization, compromise of the EMS server can enable lateral movement to managed endpoints, credential harvesting, and deployment of malware across the enterprise. Threat actors have actively leveraged this vulnerability to deploy the EKZ infostealer (disguised as a legitimate Fortinet patch), as well as ransomware families including Medusa and REvil, and the China-linked JDY botnet has also been observed exploiting this flaw (Arctic Wolf, BleepingComputer).
.exe or installer files) in EMS directories; unexpected executables or scripts dropped on the EMS server; EKZ infostealer artifacts (see PCRisk removal guide for file indicators: PCRisk).cmd.exe, powershell.exe, curl, wget); processes associated with credential dumping or lateral movement tools.Fortinet released emergency hotfixes for FortiClient EMS 7.4.5 and 7.4.6 shortly after disclosure, with instructions available in the respective release notes. The permanent fix is included in FortiClient EMS 7.4.7 and above (Fortinet PSIRT). FortiClient Cloud and FortiSASE were remediated by Fortinet and require no customer action. Prioritized remediation steps:
The vulnerability generated significant industry attention given its zero-day exploitation status and critical severity. Forbes, The Hacker News, BleepingComputer, SecurityWeek, and Ars Technica-equivalent outlets all covered the story prominently within days of disclosure (Forbes, The Hacker News). Fortinet's stock dropped approximately 7% in the days following disclosure, reflecting investor concern about the severity and active exploitation (Yahoo Finance). Security researchers on Reddit, Mastodon, and Bluesky widely shared detection tools and urged immediate patching, with the r/sysadmin and r/cybersecurity communities actively discussing the auth bypass mechanism. Arctic Wolf published a detailed follow-up report in late May 2026 documenting the EKZ infostealer campaign leveraging this vulnerability, which received broad coverage across the security community (Arctic Wolf). Multiple national CERTs including Belgium CCB, Canada CCCS, Hong Kong GovCERT, Ireland NCSC, and CERT-EU issued advisories urging immediate action.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."