critical Code Vulnerability zero-day
Fortinet FortiClient EMS Zero-Day — Active Exploitation
| CVE | CVE-2026-35616 |
| Severity | critical |
| Status | open |
| Date | April 6, 2026 |
| Affects | Fortinet FortiClient Enterprise Management Server |
| Source | cyberscoop.com |
Details
CVSS 9.8. Improper access control vulnerability actively exploited since March 31, 2026. Added to CISA KEV catalog April 6. Fortinet released an emergency hotfix but full patch still pending. Attackers can gain unauthorized access to managed endpoints.