A critical improper access control flaw in Fortinet FortiClient EMS allows unauthenticated attackers to bypass API authentication and execute unauthorized code or commands on the management server, with active exploitation observed in the wild.
Read more about Emerging Threat: (CVE-2026-35616) Fortinet FortiClient EMS Improper Access Control