Skip to main content
See every side of every news story
Published loading...Updated

New Fortinet Zero-Day Warning—Update Now, Attacks Underway

Fortinet said the flaw has a CVSS score of 9.8, and researchers found nearly 2,000 publicly exposed FortiClient EMS instances.

  • On Monday, the Cybersecurity and Infrastructure Security Agency added CVE-2026-35616 to its known exploited vulnerabilities catalog, noting the critical flaw carries a CVSS rating of 9.8.
  • Fortinet warned in a Saturday security advisory that it has seen the vulnerability being actively exploited in the wild, sharing similarities with CVE-2026-21643 disclosed in Feb.
  • On Sunday, Shadowserver scans found nearly 2,000 publicly exposed instances of FortiClient EMS, while Benjamin Harris, CEO, told CyberScoop that unknown attackers were first observed attempting to exploit the vulnerability on March 31.
  • Fortinet released an emergency software update over the weekend to address the issue, though a comprehensive patch is not yet available, and the company is communicating directly with customers to advise on necessary actions.
  • Since early 2025, CISA has added 10 Fortinet defects to its known exploited vulnerabilities catalog, and Caitlin Condon, vice president of security research at VulnCheck, noted that Fortinet solutions are popular targets for threat actors.
Insights by Ground AI

11 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

eSecurityPlanet broke the news in on Monday, April 6, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal