Fortinet patches second critical FortiClient EMS zero-day in two weeks
Fortinet released an emergency weekend patch on April 5 for CVE-2026-35616, a critical vulnerability in FortiClient EMS that is being actively exploited in the wild. This is the second unauthenticated remote code execution flaw in the endpoint management platform to come under attack within two weeks.
The vulnerability carries a CVSS score of 9.1 and affects versions 7.4.5 and 7.4.6. It is an improper access control issue (CWE-284) that allows unauthenticated attackers to bypass API authentication and authorization controls entirely, then execute arbitrary code via crafted requests.
Exploitation started March 31
According to threat intelligence firm watchTowr, exploitation attempts against this flaw were first recorded against its honeypots on March 31, 2026 - a full five days before the patch was available. Defused Cyber, which discovered the vulnerability along with researcher Nguyen Duc Anh, confirmed it observed in-the-wild exploitation earlier in the week before reporting it to Fortinet under responsible disclosure.
Fortinet has not disclosed the nature of the attacks or whether they are connected to exploitation of CVE-2026-21643, another CVSS 9.1 FortiClient EMS flaw that began seeing active exploitation last week. Both vulnerabilities share similar characteristics: unauthenticated access, remote code execution, and pre-authentication API bypasses.
Over 2,000 instances exposed
Shadowserver has identified more than 2,000 exposed FortiClient EMS instances on the public internet, with the majority located in the United States and Germany. Each of these represents a potential entry point for attackers to compromise endpoint management infrastructure at scale.
Fortinet is urging customers to apply hotfixes immediately for affected versions or upgrade to version 7.4.7 when available. The company explicitly confirmed exploitation in its advisory: “Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix.”
The holiday weekend timing
The timing of the exploitation ramp-up is notable. As watchTowr CEO Benjamin Harris pointed out, attackers consistently target holiday weekends when security teams operate at reduced capacity and detection windows stretch from hours to days. Easter weekend is no exception.
The larger concern is the pattern. Two critical unauthenticated RCE vulnerabilities in the same product within weeks suggests either a focused research effort by threat actors or deeper architectural issues in FortiClient EMS’s API layer. Organizations running this software exposed to the internet should treat this as an emergency response situation, not a routine patch cycle.
If you run FortiClient EMS 7.4.5 or 7.4.6, patch now. Attackers already have a head start.