Fortinet has issued an emergency hotfix for a critical remote unauthenticated code execution flaw in its FortiClient EMS software that is being actively exploited. 

The company published an advisory on Saturday and urged all customers who are running affected versions of the software to install the hotfix as quickly as possible. The bug affects versions 7.4.5 and 7.4.6 of FortiClient EMS. 

“An Improper Access Control vulnerability in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6,” the advisory says. 

The vulnerability (CVE-2026-35616) first emerged on Friday and though Fortinet and other researchers have confirmed it is being actively exploited, no further information on the exploit activity has been released yet. 

“A remote, unauthenticated attacker could exploit this flaw by sending specially crafted requests to the server. A successful exploit may allow the attacker to execute unauthorized code or commands,” an analysis by runZero researcher Matthew Kienow says. 

FortiClient Endpoint Management System is the company’s app for monitoring the security settings on devices that run FortiClient. Fortinet plans to release a full fix for the vulnerability in an upcoming release, FortiClient EMS 7.4.6.

VulnCheck has added the vulnerability to its known exploited vulnerabilities catalog. CISA added it to its KEV on Monday, as well.