Fortinet FortiClient EMS Improper Access Control Vulnerability
- Severity
- Critical9.8CVSS 3.1, Critical
- Known exploited
- Known exploitedFederal remediation due date: 9 Apr 2026
- Exploit prediction
- 9%
- Published
- 4 Apr 2026Updated 24 Jul 2026 · Last verified 30 Sept 2026
Known remediation
Fixed releases per branch, as the vendor states them. Patcharo never infers a fix.
Fortinet FortiClient EMS
Vendor advisory- 7.4Fixed after 7.4.6
Workaround / Vendor remediation
Vendor remediation · FortiClient EMS
Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.7 or above
Description
Title, description and vendor guidance are quoted from the source records.
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Weakness: CWE-284
Known exploited
Added to CISA KEV on 6 Apr 2026
Federal remediation due date: 9 Apr 2026
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit prediction
9% probability of exploitation in the next 30 days (percentile 95%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the source states, per branch
Versions matched by Patcharo
Fortinet FortiClient EMSSource: Fortinet (CVE record)
| Branch | Affected | Fixed in |
|---|---|---|
| 7.4 | 7.4.5 – 7.4.6 | Fixed after 7.4.6 |
Versions not listed are stated unaffected by the vendor.
References
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Fortinet (CVE record)
- Fortinet (CVE record) · 30 Sept 2026 at 00:17 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 30 Sept 2026 at 00:17 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 28 Sept 2026 at 07:02 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 30 Sept 2026 at 00:17 UTC · Parser patcharo-epss/1.0.0
Last verified: 30 Sept 2026 at 00:17 UTC