CVE-2026-35616: Fortinet FortiClientEMS Pre-Authentication API Bypass Leading to Remote Code Execution (CISA KEV) — Threadlinqs Intelligence
As of 2026-05-30, CVE-2026-35616: Fortinet FortiClientEMS Pre-Authentication API Bypass Leading to Remote Code Execution (CISA KEV) is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 14 indicators of compromise.
Threat ID: TL-2026-0325 · Severity: CRITICAL · CVSS: 9.1 · Status: ACTIVE · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Critical improper access control vulnerability (CVE-2026-35616, CVSS 9.1) in Fortinet FortiClientEMS 7.4.5 through 7.4.6 allows unauthenticated remote attackers to bypass API authentication and
CVE-2026-35616 is a critical pre-authentication API access bypass vulnerability in Fortinet FortiClient Endpoint Management Server (EMS) versions 7.4.5 through 7.4.6. The vulnerability resides in the API layer of FortiClient EMS, where improper access control (CWE-284) allows unauthenticated attackers to interact with specific API endpoints without valid credentials. By sending specially crafted requests to the FortiClient EMS server interface, attackers can completely bypass the server's authentication and authorization controls, escalate privileges, and execute arbitrary code or commands on the affected system.
FortiClient EMS is the centralized management platform used by enterprises to deploy, configure, and monitor FortiClient endpoint security agents across their entire fleet. A compromise of this server provides attackers with effective god-mode capability — the ability to push malicious configurations, disable endpoint protections, execute commands at scale across all managed endpoints, and move laterally throughout the enterprise environment.
The vulnerability was discovered independently by Simo Kohonen of Defused Cyber and Nguyen Duc Anh, who observed active zero-day exploitation before responsible disclosure. watchTowr confirmed that exploitation attempts were first recorded against their honeypots on March 31, 2026. Fortinet published advisory FG-IR-26-099 and released emergency out-of-band hotfixes on April 4-5, 2026, confirming active exploitation in the wild.
CISA added CVE-2026-35616 to the Known Exploited Vulnerabilities (KEV) catalog on April 6, 2026, ordering all Federal Civilian Executive Branch (FCEB) agencies to patch by April 9, 2026 — an unusually tight three-day remediation window reflecting the severity and active exploitation status.
This is the second critical FortiClientEMS vulnerability exploited in rapid succession. CVE-2026-21643, a pre-authentication SQL injection flaw in version 7.4.4, was disclosed in late March 2026 and is also under active exploitation. The two vulnerabilities together represent a sustained campaign targeting FortiClientEMS as a high-value enterprise entry point. Internet security watchdog Shadowserver has identified over 2,000 exposed FortiClientEMS instances online, with the majority located in the United States and Germany.
A public proof-of-concept has been identified on GitHub, though it has not been independently verified by major research firms as of publication. The combination of a public PoC, active exploitation, and the central role of EMS in enterprise endpoint management makes this an extremely high-priority patching target.
Post-exploitation capabilities include: manipulation of endpoint security policies across the entire managed fleet, deployment of malicious payloads to connected FortiClient agents, extraction of endpoint inventory data (hostnames, IPs, OS versions, serial numbers), access to ZTNA certificates and SAML configurations, creation of persistent backdoor admin accounts, and lateral movement through the broader enterprise network.
Target sectors: government, financial, healthcare, telecommunications, technology, defense, energy, education, manufacturing, critical-infrastructure
Target regions: North America, Europe, Asia Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 14 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-35616, T1190, T1059, T1059, T1059, T1548, T1078, T1136, T1562, T1562, T1555