{"id":13905,"date":"2026-05-03T12:00:47","date_gmt":"2026-05-03T12:00:47","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/05\/03\/fortinet-cve-2026-35616-forticlient-ems-kritische-luecken\/"},"modified":"2026-07-04T11:54:38","modified_gmt":"2026-07-04T11:54:38","slug":"fortinet-cve-2026-35616-forticlient-ems-kritische-luecken","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/fortinet-cve-2026-35616-forticlient-ems-kritische-luecken\/","title":{"rendered":"CVE-2026-35616: Critical FortiClient EMS Flaws &#8211; DACH IT Alert"},"content":{"rendered":"<p class=\"article-figcaption\" style=\"text-align:center;font-style:italic;color:#b8c5ce;font-size:0.92em;margin-top:-0.5em;margin-bottom:1.5em;line-height:1.4;\">Cybersecurity monitor with Code-Stream. The Fortinet vulnerabilities in FortiClient EMS are hitting DACH IT teams at a time when patch frequency is already at its limit. <span style=\"color:#b8c5ce;opacity:0.85;\">(Photo: T. Miroshnichenko \/ Pexels)<\/span><\/p>\n<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">7 Min. Read<\/p>\n<p><strong>Fortinet has patched two critical vulnerabilities in FortiClient EMS within three weeks. CVE-2026-35616, with a CVSS score of 9.1, allows for Pre-Authenticated Remote Code Execution &#8211; Honeypot data from Shadowserver shows active exploit attempts since March 31, 2026. The pattern indicates: FortiClient EMS is structurally exposed, and patch frequency alone is no longer sufficient as a sole measure.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:1px solid rgba(105,216,237,0.3);padding-bottom:14px;border-bottom:2px solid rgba(105,216,237,0.25);\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Two critical patches in three weeks.<\/strong> CVE-2026-35616 (CVSS 9.1, Pre-Auth RCE) and a subsequent advisory on a privilege escalation vector in FortiClient EMS &#8211; this is not a one-off event, but a pattern.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">CISA KEV inclusion on April 2, 2026.<\/strong> Federal agencies in the USA have a 7-day patch deadline. DACH IT teams without similar governance must set their own deadline.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Exploit pattern active since March 31.<\/strong> Shadowserver and GreyNoise are registering probe traffic against exposed FortiClient EMS installations. Those running EMS without network segmentation are directly exposed.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Patching alone is not enough.<\/strong> JDBC injection as an attack vector in FortiClient EMS means: unauthenticated users can execute SQL queries. Network access control on the EMS port is a critical immediate measure.<\/li>\n<\/ul>\n<\/div>\n<p><strong>Related: <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/source-code-breaches-when-hackers-outpace-security-vendors\/\">Source-Code Breaches: When Attackers Know the Security Vendor Before the Patch<\/a><\/strong><\/p>\n<p><strong>What is FortiClient EMS?<\/strong> FortiClient EMS (Endpoint Management Server) is Fortinet&#8217;s central management platform for the FortiClient agent on endpoints. EMS controls compliance policies, VPN configurations, and security posture assessments for all managed endpoints in the network &#8211; making it a highly privileged target for attackers.<\/p>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#202528;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/source-code-breaches-when-hackers-outpace-security-vendors\/\" style=\"color:#333;text-decoration:underline;\">Source-Code Breaches: When the Security Vendor is Compromised Before the Patch<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/01\/cve-2026-3854-github-enterprise-rce-git-push-patch-pflicht\/\" style=\"color:#333;text-decoration:underline;\">CVE-2026-3854: GitHub Enterprise RCE &#8211; 88% unpatched<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:20px;\">What sets CVE-2026-35616 apart from previous FortiClient vulnerabilities<\/h2>\n<p>FortiClient EMS has a documented history of vulnerabilities. CVE-2023-48788 was an SQL injection flaw with a CVSS score of 9.8, which was massively exploited in 2024 and added to the CISA KEV list. The pattern repeats: JDBC-based injection, pre-auth access, critical CVSS score.<\/p>\n<p>CVE-2026-35616 targets the same attack vector as its predecessor \u2013 JDBC database access without prior authentication. According to Fortinet&#8217;s advisory on March 29, 2026, an unauthenticated attacker can execute SQL code on the EMS database via manipulated HTTP requests. The direct result: system access to the EMS server with database rights.<\/p>\n<p>What sets this incident apart from the 2023 predecessor: the time from patch release to honeypot activity was shorter this time. Shadowserver registered the first exploit attempts against CVE-2026-35616 on March 31, 2026 \u2013 two days after the advisory. For CVE-2023-48788, it took around two weeks before the first mass exploitation.<\/p>\n<div style=\"background:#f9f9f9;border-radius:8px;padding:24px 28px;margin:28px 0;\">\n<p style=\"margin:0 0 14px 0;font-size:0.8em;font-weight:700;text-transform:uppercase;letter-spacing:0.15em;color:#69d8ed;\">Key figures on the threat situation<\/p>\n<div style=\"display:flex;flex-wrap:wrap;gap:20px;\">\n<div style=\"flex:1;min-width:150px;text-align:center;\">\n<p style=\"font-size:2em;font-weight:800;color:#003340;margin:0;\">CVSS 9.1<\/p>\n<p style=\"color:#b8c5ce;font-size:0.82em;margin:4px 0 0 0;\">Critical score for CVE-2026-35616, Pre-Auth RCE via JDBC Injection<\/p>\n<\/div>\n<div style=\"flex:1;min-width:150px;text-align:center;\">\n<p style=\"font-size:2em;font-weight:800;color:#003340;margin:0;\">2 Days<\/p>\n<p style=\"color:#b8c5ce;font-size:0.82em;margin:4px 0 0 0;\">from advisory to first honeypot exploit attempts (Shadowserver)<\/p>\n<\/div>\n<div style=\"flex:1;min-width:150px;text-align:center;\">\n<p style=\"font-size:2em;font-weight:800;color:#003340;margin:0;\">7 Days<\/p>\n<p style=\"color:#b8c5ce;font-size:0.82em;margin:4px 0 0 0;\">Mandatory patch for US federal agencies after CISA KEV inclusion on April 2, 2026<\/p>\n<\/div>\n<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:20px;\">Why FortiClient EMS is structurally exposed<\/h2>\n<p>FortiClient EMS is inherently a high-privilege system. It knows all managed endpoints, their compliance status, VPN connections, and security policies. If an attacker compromises EMS, they not only gain access to a server \u2013 they obtain a map of the entire endpoint inventory and levers to manipulate security policies.<\/p>\n<p>The real issue is the deployment practice: many DACH companies operate FortiClient EMS without strict network segmentation \u2013 with direct access from the internal network or, worse, from DMZ segments. However, EMS is a management system that should never be directly accessible from the user LAN.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;background:#003340;color:#fff;border-radius:4px;margin:28px 0;padding:20px 24px;\">\n<p style=\"margin:0;line-height:1.7;\">&#8220;Every other FortiClient EMS deployment we see during penetration tests has the management port directly accessible from the internal network. This is a design flaw, not a configuration error.&#8221;<\/p>\n<p><cite style=\"display:block;margin-top:10px;font-size:0.82em;color:#69d8ed;font-style:normal;\">&#8211; Alec Chizhik, securitytoday.de<\/cite>\n<\/p><\/blockquote>\n<h2 style=\"margin-top:48px;margin-bottom:20px;\">The Patch and Hardening Checklist for DACH Teams<\/h2>\n<p>Check patch status first &#8211; but patching alone won&#8217;t solve the structural problem. A combined measures list:<\/p>\n<ol style=\"line-height:2.0;margin:0 0 20px 0;padding-left:22px;\">\n<li style=\"margin-bottom:10px;\"><strong>Immediate Action: Check EMS version.<\/strong> Affected are FortiClient EMS versions 7.4.0 to 7.4.1 and 7.2.0 to 7.2.7. The fix is included in 7.4.2 and 7.2.8. Version check: <span style=\"font-family:monospace;background:#f4f4f4;padding:1px 5px;border-radius:3px;font-size:0.92em;\">diagnose sys version<\/span> in the EMS-CLI.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Restrict network access.<\/strong> EMS port 443 should be accessible exclusively from a dedicated management segment &#8211; not from the general user LAN. Check and adjust firewall rules if necessary.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Exposure check: Is EMS accessible from the internet?<\/strong> Query Shodan or FOFA for your own external IP. Publicly accessible EMS instances are an immediate priority.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Log review for exploit attempts.<\/strong> Fortinet&#8217;s IOC list for CVE-2026-35616 contains specific HTTP request patterns. SIEM search for these patterns in the last 30 days.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Plan a two-patch cadence.<\/strong> Fortinet released two critical advisories in three weeks. Teams running EMS should define a dedicated patch track with a max. 72h reaction time for Fortinet criticals.<\/li>\n<\/ol>\n<div style=\"display:grid;grid-template-columns:1fr 1fr;gap:20px;margin:28px 0;\">\n<div style=\"background:#f0f7ff;border-radius:8px;padding:20px 24px;\">\n<p style=\"font-size:0.75em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#1a3a5c;margin:0 0 12px 0;\">Completed After Patching<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.9;color:#333;\">\n<li>RCE vector CVE-2026-35616 closed<\/li>\n<li>Privilege escalation patch (Advisory 2) applied<\/li>\n<li>Fortinet support status for version confirmed<\/li>\n<li>Patch documentation created for audit trail<\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#fff0f0;border-radius:8px;padding:20px 24px;\">\n<p style=\"font-size:0.75em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#8b0000;margin:0 0 12px 0;\">Structurally Still Open<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.9;color:#333;\">\n<li>Network segmentation for EMS port not yet implemented?<\/li>\n<li>Log review for exploit attempts before patch date<\/li>\n<li>Incident response plan for compromised EMS instance missing<\/li>\n<li>No dedicated patch SLA defined for Fortinet criticals<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:20px;\">What This Pattern Means for DACH IT Teams<\/h2>\n<p>Fortinet is not an isolated case. Check Point, Palo Alto, Ivanti, SonicWall &#8211; all major security vendors have published critical vulnerabilities in their management platforms in the last 18 months that have been actively exploited. The pattern is consistent: management software as a target.<\/p>\n<p>The strategic consequence: Security management software must be treated with the same hardening standards as privileged Active Directory components. This means: Management ports not accessible from the user LAN, dedicated patch track, daily log monitoring for anomalies.<\/p>\n<p>Teams that have not yet implemented these basic principles for all their security management platforms should use the current Fortinet CVE wave as a trigger for a management surface hardening project &#8211; not as a one-time patch event.<\/p>\n<p style=\"font-size:0.9em;color:#b8c5ce;margin-bottom:28px;\"><em>Sources: Fortinet PSIRT Advisory CVE-2026-35616 (March 29, 2026) | CISA KEV (April 2, 2026) | Shadowserver Foundation Exploit Telemetry<\/em><\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Which FortiClient EMS versions are affected by CVE-2026-35616?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Affected are FortiClient EMS 7.4.0 to 7.4.1 and 7.2.0 to 7.2.7. The patched versions are 7.4.2 (fixes 7.4.x branch) and 7.2.8 (fixes 7.2.x branch). Older versions should be brought to the current minor branch according to Fortinet&#8217;s upgrade path documentation.<\/p>\n<\/details>\n<details>\n<summary><strong>How can I tell if my EMS instance has already been compromised?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Fortinet&#8217;s PSIRT advisory contains specific Indicators of Compromise (IOC). Search the EMS web server log for unusual HTTP POST requests to database access paths. Additionally, new local administrator accounts or unknown scheduled tasks on the EMS host indicate post-exploitation activity.<\/p>\n<\/details>\n<details>\n<summary><strong>Do I need to disable EMS until the patch is applied?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">If EMS is not accessible from the Internet and access is restricted to a dedicated management segment, temporary disabling is not mandatory &#8211; network isolation significantly reduces the risk. For EMS with Internet access: immediately set up a firewall block and apply the patch as soon as possible.<\/p>\n<\/details>\n<details>\n<summary><strong>Does the CISA patch deadline also apply to European companies?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No, the CISA KEV patch deadline of 7 days only applies to US federal agencies. However, it is a useful benchmark: if US federal agencies consider 7 days reasonable, this should be a maximum for DACH companies with a similar compliance level, not a guideline.<\/p>\n<\/details>\n<details>\n<summary><strong>What if we use FortiClient EMS as a cloud service?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Fortinet&#8217;s cloud-managed variant (FortiCloud EMS) is patched by Fortinet. Check if the instance is actually cloud-managed &#8211; many companies operate &#8220;cloud&#8221; as a self-managed VM in their own cloud environment. In this case, all self-managed patching responsibilities apply.<\/p>\n<\/details>\n<div style=\"border-top:2px solid rgba(105,216,237,0.3);padding:20px 0;margin-top:40px;\">\n<p style=\"font-size:0.75em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#69d8ed;margin:0 0 8px 0;\">Network<\/p>\n<p style=\"line-height:1.7;font-size:0.9em;color:#444;margin:0;\"><strong>Alec Chizhik<\/strong> writes for SecurityToday about vulnerability analyses, exploit telemetry, and operational security decisions for DACH IT teams<\/p>\n<\/div>\n<p style=\"text-align:right;font-style:italic;color:#b8c5ce;\"><em>Title image source: Pexels \/ Tima Miroshnichenko<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"FortiClient EMS has received two critical patches within three weeks. CVE-2026-35616 (CVSS 9.1, Pre-Auth RCE) has shown exploits since March 31, 2026.","protected":false},"author":10,"featured_media":14341,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Fortinet CVE-2026-35616 FortiClient EMS","_yoast_wpseo_title":"Fortinet CVE-2026-35616: Two Critical FortiClient EMS Flaws in Weeks - What It M","_yoast_wpseo_metadesc":"Fortinet CVE-2026-35616: Pre-Auth RCE CVSS 9.1 in FortiClient EMS. Exploits active since 31.03.2026. CISA KEV listed.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/fortinet-cve-2026-35616-forticlient-ems-kritische-luecken-dach-it-teams-cover-hero-2-scaled.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/fortinet-cve-2026-35616-forticlient-ems-kritische-luecken-dach-it-teams-cover-hero-2-scaled.jpg","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255],"tags":[],"class_list":["post-13905","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en"],"evm_reading_time_minutes":8,"wpml_language":"en","wpml_translation_of":13895,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=13905"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13905\/revisions"}],"predecessor-version":[{"id":19609,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13905\/revisions\/19609"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/14341"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=13905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=13905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=13905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}