CVE-2026-35616:
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Score
A numerical rating that indicates how dangerous this vulnerability is.
9.8CriticalA numerical rating that indicates how dangerous this vulnerability is.
- Published Date:Apr 4, 2026
- CISA KEV Date:Apr 6, 2026
- Industries Affected:20
Armis Early Warning:
2 Days
Threat Predictions
- EPSS Score:0.0
- EPSS Percentile:10%
Exploitability
- Score:3.9
- Attack Vector:NETWORK
- Attack Complexity:LOW
- Privileges Required:NONE
- User Interaction:NONE
- Scope:UNCHANGED
Impact
- Score:5.9
- Confidentiality Impact:HIGH
- Integrity Impact:HIGH
- Availability Impact:HIGH
Description Preview
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Armis Early Warning
Armis Early Warning provides proactive threat intelligence and early detection capabilities.Click here to learn more.
- Armis Alert Date:*No Data*
- CISA KEV Date:Apr 6, 2026
- Days Early:2 Days
Industries Affected
Below is a list of industries most commonly impacted or potentially at risk based on intelligence.
Low