1.
bishopfox.com | vulnerability | Critical | [Actively exploited] | | original ↗ | #vulnerability-research | #authentication-bypass | #certificate-validation | #forticlient-ems
CVE-2026-35616: FortiClient EMS 7.4.5-7.4.6 trusts spoofable headers as cert auth and skips signature checks, letting attackers forge certificates for API access; exploited in the wild.
Skip to content