Fortinet FortiClient EMS Improper Access Control Vulnerability The supported impact is compromise of enterprise management systems. Exploitation evidence is classified as confirmed in the wild.
Why This Matters
Publisher reporting describes a concrete security event. BugSkan could not yet bind it to a CVE or affected version, so treat the source details as the current record.
Recommended Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Confirm whether FortiClient EMS is present in your environment and review the affected configuration.
CVE: CVE-2026-35616NVD CVSS: 9.8 CRITICALFIRST EPSS: 0.907
Affected
FortinetFortiClient EMSMarchNewCVE-2026-35616