CVE-2026-35616
CRITICAL
CVSS: 9.8
EPSS: 90.7%
VulnCheck KEV
Weaponized
CWE-284
T1078
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Published: 2026-04-04