INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Fortinet Zero-Day Exploit Patch Released

| 2026-04-06 21:12 CRITICAL HIGH
Executive Summary AI-generated
The zero-day vulnerability CVE-2026-35616 has been added to the Cybersecurity and Infrastructure Security Agency's known exploited vulnerabilities catalog, with a CVSS rating of 9.8. This critical context was first disclosed by Fortinet on Monday, March 31, as an improperly accessed control vulnerability in its FortiClient EMS software. The exploit zero-day flaw follows another FortiClient EMS vulnerability, tracked as CVE-2026-21643, that came under attack late last month. Experts warn of growing attacker interest and potential broader targeting due to the recent disclosure.
Technical Mitigations AI-generated
* Implement a patch or update for FortiClient EMS versions 7.4.5 and 7.4.6 to prevent exploitation of CVE-2026-35616. * Monitor customer devices for signs of vulnerability, such as suspicious activity or unusual network connections, and take prompt action if necessary. * Use secure protocols (e.g., HTTPS) when communicating with customers' endpoints to reduce the risk of exploitation by attackers. * Regularly review and update software configurations and settings to ensure that FortiClient EMS is properly configured and patched against known vulnerabilities.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-64155CVE-2025-64155 CVE-2025-59718CVE-2025-59718 CVE-2026-21643CVE-2026-21643 CVE-2026-35616CVE-2026-35616 CVE-2025-64446CVE-2025-64446
Target & Sectors
Global Scope
Incident Timeline
‎early 2025
Fortinet's 10 known exploited vulnerabilities were discovered and reported to CISA by customers in early 2025.
general_metric 10 Fortinet defects
‎Feb. 6
Threat actors exploited a newly discovered zero-day vulnerability in Fortinet customers' systems, which shares similarities with CVE-2026-21643.
vulnerability CVE-2026-21643
organisation SQL
‎2026/03/07
Threat actors exploited CVE-2026-21643, a zero-day vulnerability in Fortinet customers' FortiClient EMS systems.
vulnerability CVE-2026-21643
‎2026/03/30
Threat actors used a recently disclosed zero-day vulnerability in Fortinet's software to target affected customers.
vulnerability CVE-2026-21643
‎March 31
Unknown attackers attempted to exploit a zero-day vulnerability in Fortinet customers' systems on March 31.
organisation CyberScoop
‎2026/04/05
Threat actors exploited a recently disclosed zero-day vulnerability in Fortinet products.
‎April 6
Fortinet issued a hotfix on April 6 to address the exploited zero-day.
organisation Fortinet
‎2026-3055
Threat actors exploited CVE 2026-3055 in Citrix NetScaler ADC and NetScaler Gateway.
organisation Citrix NetScaler ADC
organisation NetScaler Gateway
‎2026/04/06
Fortinet released a hotfix for FortiClient EMS versions 7.4.5 and 7.4.6 to address CVE-2026-35616, an improperly accessed control vulnerability that allows unauthenticated access through crafted requests.
organisation Fortinet
organisation FortiClient Endpoint Management
organisation EMS
organisation Defused
organisation API
organisation FortiClient EMS
infrastructure 7.4.5
infrastructure 7.4.6
organisation Shadowserver
organisation CVE-2025-64155
organisation CVE-2025
organisation FortiWeb
infrastructure Fortigate
organisation PoC
organisation GitHub
organisation FortiCloud
organisation Oracle's
organisation Fusion Middleware Has Critical
‎April 9
Federal civilian executive branch agencies must address the Fortinet customer issue by April 9 due to a zero-day exploit.
attribution FCEB
Tactical Metrics
Metrics
infrastructure
‎7.4.5
Software Version
Metrics
infrastructure
‎7.4.6
Software Version
Metrics
infrastructure
‎Fortigate
Affected Product