← All CVEs NewScan detects
critical

CVE-2026-35616

FortiClient EMS improper access control - unauthenticated code/command execution via crafted requests

Severity
critical
Affected product
FortiClient EMS
Affected versions
FortiClient EMS all versions before the fix
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the FortiClient EMS appliance and reports this CVE when the detected version falls inside the affected range below.

Fortinet warned of active exploitation in Apr 2026. Advisory only: no confirmed fixed build recorded here and no anonymous version source.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →