API Authentication Bypass in FortiClient EMS 7.4.5-7.4.6–CVE-2026-35616
bishopfox.com | vulnerability | Critical | Actively exploited | CVE-2026-35616 | #vulnerability-research | #authentication-bypass | #certificate-validation | #forticlient-ems | #cve-2026-35616 | #fortinet | #exploited-in-the-wild
Summary
CVE-2026-35616: FortiClient EMS 7.4.5-7.4.6 trusts spoofable headers as cert auth and skips signature checks, letting attackers forge certificates for API access; exploited in the wild.
- CVSS
- 9.8
- Published
- Collected
Skip to content