Critical Analysis: CVE-2026-35616 - Fortinet FortiClient EMS Improper Access Control Vulnerabili... — April 12, 2026

Published 12 Apr 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news

AGMP Partners Alright, let's cut through the noise and talk about CVE-2026-35616, the Fortinet FortiClient EMS improper access control vulnerability announced on April 12, 2026. As someone knee-deep in vulnerability research and incident response, this one has been on my radar, and for good reason. It’s not just another patching exercise; it’s a critical flaw that, in the wrong hands, could seriously compromise an enterprise environment. What we're looking at here is a gaping hole in an endpoint management system, effectively a control plane for a significant portion of an organization's device fleet. The CVSS score assigned is 9.8 (Critical), and frankly, that feels about right given the ease of exploitability and the potential impact. Initial Discovery and Context This vulnerability surfaced through private research, likely an independent security researcher or a red team exercise, and