Full Breakdown
Fortinet Faces Critical Security Flaws Amid Active Exploitation
4/5/2026, 11:46:33 PM
Overview of the Vulnerabilities
Fortinet has issued urgent patches for two critical vulnerabilities affecting its FortiClient Endpoint Management Server (EMS). The first vulnerability, tracked as CVE-2026-35616, has a CVSS score of 9.1 and is characterized as a pre-authentication API access bypass that allows privilege escalation. This flaw enables unauthenticated attackers to execute unauthorized code or commands through crafted requests. The affected versions are FortiClient EMS 7.4.5 and 7.4.6, with a hotfix now available, while a full patch is expected in version 7.4.7. The vulnerability was discovered by Simo Kohonen from Defused Cyber and Nguyen Duc Anh, who reported observing zero-day exploitation earlier this week.
The second vulnerability, CVE-2026-21643, also carries a CVSS score of 9.1 and allows unauthenticated threat actors to execute arbitrary code on unpatched systems via specially crafted HTTP requests. This flaw has been actively exploited as recently as four days ago, indicating a troubling trend for Fortinet, which serves over 900,000 customers globally.
Timeline of Exploitation
- March 31, 2026: Initial exploitation attempts against CVE-2026-35616 were recorded by watchTowr.
- April 2026: Reports of active exploitation of CVE-2026-21643 emerge, coinciding with the discovery of CVE-2026-35616.
Implications for Users
The rapid exploitation of these vulnerabilities highlights significant risks for organizations using FortiClient EMS. Security experts emphasize the need for immediate action. Benjamin Harris, CEO of watchTowr, noted that attackers often exploit vulnerabilities during holiday weekends when security teams are less vigilant. He stated, "The timing of the ramp-up of in-the-wild exploitation of this zero-day is likely not coincidental."
Criticism of Fortinet's Security Measures
Critics have expressed disappointment over the recurrence of unauthenticated vulnerabilities within Fortinet's products. The recent emergence of two critical flaws in quick succession raises concerns about the company's security protocols. Experts urge organizations to treat these vulnerabilities as emergencies, advising them to apply the hotfix immediately rather than delaying action.
Official Statements & Responses
Fortinet has acknowledged the critical nature of these vulnerabilities and has urged customers to install the hotfix for FortiClient EMS versions 7.4.5 and 7.4.6. The company has not confirmed whether the same threat actor is exploiting both vulnerabilities, but the urgency of the situation has been made clear.
Verbatim Quotes
- “An improper access control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests,” — Fortinet Advisory
Conclusion
The recent vulnerabilities in Fortinet's EMS products underscore the ongoing challenges in cybersecurity. Organizations utilizing FortiClient EMS are strongly advised to take immediate action to mitigate risks associated with these critical flaws.
