SB2026040404 - Authentication bypass and remote code execution in Fortinet FortiClientEMS



SB2026040404 - Authentication bypass and remote code execution in Fortinet FortiClientEMS

Published: April 4, 2026

Security Bulletin ID SB2026040404
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing authorization (CVE-ID: CVE-2026-35616)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authorization checks. A remote non-authenticated attacker can send a specially crafted HTTP request to certain API endpoint and execute arbitrary commands on the system.

Note, the vulnerability is being actively exploited in the wild. 


Remediation

Install update from vendor's website.