9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
CVE-2026-35616 - FortiClient EMS Pre-Authentication API Bypass to RCE TL;DR A critical authentication bypass in Fortinet FortiClient EMS 7.4.5 and 7.4.6 allows a completely unauthenticated, remote attacker to bypass API authentication by spoofing a...
Basic Information
ID
F57708C0-5A99-5B20-9856-EF70613A9E51
Published
Apr 13, 2026 at 18:49
Modified
Apr 13, 2026 at 18:55