CVE-2026-35616

9.8CRITICAL
公開日: 4/4/2026更新日: 4/4/2026

CISA既知の悪用された脆弱性

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

必要な対応:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

期限:

2026-04-09

説明

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

AI分析AIによる分析

参照