Impacted Product
FortiClientEMS 7.4.5, 7.4.6
Summary
An Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6, by following the instructions at:
https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484 - for FortiClientEMS 7.4.5
https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484 - for FortiClientEMS 7.4.6
Upcoming FortiClientEMS 7.4.7 will also include a fix for this issue. In the meantime the hotfix above is sufficient to prevent it entirely.
Timeline
2026-04-04: Initial publication by FortiGuard Labs, CVE.org
2026-04-06: Listed by CISA in the Known Exploited Vulnerabilities Catalog to patch by 2026-04-09
I haven’t seen yet any comments how it’s been observed, IoC, or PoCs, or threat actor attribution, so I thought I’d make a post for this