CVE-2026-35616
CRITICAL KEV NUCLEIFortinet FortiClientEMS 7.4.5-7.4.6 - Command Injection
Title source: llmDescription
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Exploits (8)
github
NO CODE
1 stars
by Hex0rc1st · pythonpoc
https://github.com/Hex0rc1st/CVE_POC_monitor/tree/main/article/uploads/demo_1776759104/【已复现】FortiClientEMS API 身份验证和授权绕过漏洞(CVE-2026-35616)
Nuclei Templates (1)
FortiClient EMS - Authentication Bypass
HIGHVERIFIEDby ritikchaddha
Shodan:
http.favicon.hash:-800551065
Scores
CVSS v3
9.8
EPSS
0.3512
EPSS Percentile
97.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2026-04-06
VulnCheck KEV
2026-04-04
ENISA EUVD
EUVD-2026-18963
CWE
CWE-284
Status
published
Products (3)
fortinet/forticlientems
7.4.5
fortinet/forticlientems
7.4.6
Fortinet/FortiClientEMS
7.4.5 - 7.4.6
Published
Apr 04, 2026
KEV Added
Apr 06, 2026
Tracked Since
Apr 04, 2026