Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Authentication Bypass Zero‑Day (CVE‑2026‑35616) in FortiClient Triggers Emergency Patch

Fortinet released an emergency patch for CVE‑2026‑35616, a critical authentication‑bypass flaw in FortiClient that is already being exploited in the wild. The vulnerability threatens any organization that relies on FortiClient for endpoint protection or VPN access, creating a direct supply‑chain risk for third‑party risk managers.

LiveThreat™ Intelligence · 📅 April 07, 2026· 📰 darkreading.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
darkreading.com

Critical Authentication Bypass Zero‑Day (CVE‑2026‑35616) in FortiClient Threatens Enterprise Endpoints

What It Is — Fortinet disclosed an authentication‑bypass vulnerability (CVE‑2026‑35616) in its FortiClient endpoint protection and VPN software. The flaw allows an unauthenticated attacker to bypass login controls and gain full client privileges. Exploitability — Active exploitation has been observed in the wild; a proof‑of‑concept is publicly available. The CVSS v3.1 base score is 9.8 (Critical).

Affected Products — FortiClient 7.x (Windows, macOS, Linux) and any integrated FortiOS VPN deployments.

TPRM Impact — FortiClient is a common third‑party security layer for many SaaS and on‑premise environments. A breach could cascade to partner networks, expose credential stores, and undermine the security posture of downstream vendors.

Recommended Actions –

  • Deploy Fortinet’s emergency patch immediately on all FortiClient installations.
  • Enforce multi‑factor authentication for VPN access pending full remediation.
  • Conduct a rapid inventory of all assets using FortiClient and verify patch compliance.
  • Review logs for anomalous authentication attempts during the window of vulnerability exposure.
  • Update third‑party risk registers to reflect the elevated supply‑chain risk from FortiClient.

Source: Dark Reading

📰 Original Source
https://www.darkreading.com/vulnerabilities-threats/fortinet-emergency-patch-forticlient-zero-day ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →