wid-sec-w-2026-0962
·
Published 2026-04-06
·
View on BSI CERT-Bund ↗
Fortinet FortiClient EMS: Vulnerability allows Code execution
CVSS 9.8
CRITICAL
CISA KEV — Known Exploited
Risk Summary
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
CVEs (1)
Affected Vendors
Fortinet
Affected Products (2)
Fortinet
·
FortiClient
EMS <7.4.7
Fortinet
·
FortiClient
EMS 7.4.7
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more