Apr 06, 2026 • Rob Wright
Fortinet Issues Emergency Patch for FortiClient Zero-Day
Fortinet has released an emergency patch for a critical authentication bypass vulnerability, tracked as CVE-2026-35616, affecting FortiClient. The flaw is...
Executive Summary
Fortinet has released an emergency patch for a critical authentication bypass vulnerability, tracked as CVE-2026-35616, affecting FortiClient. The flaw is being actively exploited in the wild, making immediate patching a priority. This vulnerability represents the latest in a series of Fortinet security flaws that have been targeted by threat actors. Organizations using FortiClient should apply the emergency patch immediately to prevent potential unauthorized access and system compromise. The vulnerability allows attackers to bypass authentication mechanisms, potentially enabling full system access without valid credentials.
Summary
The authentication bypass flaw, tracked as CVE-2026-35616, is the latest in a series of Fortinet vulnerabilities that have been exploited in the wild.
Published Analysis
Fortinet has released an emergency patch for a critical authentication bypass vulnerability, tracked as CVE-2026-35616, affecting FortiClient. The flaw is being actively exploited in the wild, making immediate patching a priority. This vulnerability represents the latest in a series of Fortinet security flaws that have been targeted by threat actors. Organizations using FortiClient should apply the emergency patch immediately to prevent potential unauthorized access and system compromise. The vulnerability allows attackers to bypass authentication mechanisms, potentially enabling full system access without valid credentials. The authentication bypass flaw, tracked as CVE-2026-35616, is the latest in a series of Fortinet vulnerabilities that have been exploited in the wild. The authentication bypass flaw, tracked as CVE-2026-35616, is the latest in a series of Fortinet vulnerabilities that have been exploited in the wild.
Linked Entities
- CVE-2026-35616