critical
CVE-2026-35616
FortiClient EMS improper access control - unauthenticated code/command execution via crafted requests
- Severity
- critical
- Affected product
- FortiClient EMS
- Affected versions
- FortiClient EMS all versions before the fix
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the FortiClient EMS appliance and reports this CVE when the detected version falls inside the affected range below.
Fortinet warned of active exploitation in Apr 2026. Advisory only: no confirmed fixed build recorded here and no anonymous version source.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →