CVE-2026-35616

9.8CRITICAL
发布于: 4/4/2026更新于: 4/4/2026

CISA已知被利用漏洞

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

所需操作:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

截止日期:

2026-04-09

描述

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

AI分析AI驱动

参考资料