HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Authentication Bypass Zero‑Day (CVE‑2026‑35616) in FortiClient Triggers Emergency Patch

Fortinet released an emergency patch for CVE‑2026‑35616, a critical authentication‑bypass flaw in FortiClient that is already being exploited in the wild. The vulnerability threatens any organization that relies on FortiClient for endpoint protection or VPN access, creating a direct supply‑chain risk for third‑party risk managers.

LiveThreat™ Intelligence · 📅 April 07, 2026· 📰 darkreading.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
darkreading.com

Critical Authentication Bypass Zero‑Day (CVE‑2026‑35616) in FortiClient Threatens Enterprise Endpoints

What It Is — Fortinet disclosed an authentication‑bypass vulnerability (CVE‑2026‑35616) in its FortiClient endpoint protection and VPN software. The flaw allows an unauthenticated attacker to bypass login controls and gain full client privileges. Exploitability — Active exploitation has been observed in the wild; a proof‑of‑concept is publicly available. The CVSS v3.1 base score is 9.8 (Critical).

Affected Products — FortiClient 7.x (Windows, macOS, Linux) and any integrated FortiOS VPN deployments.

TPRM Impact — FortiClient is a common third‑party security layer for many SaaS and on‑premise environments. A breach could cascade to partner networks, expose credential stores, and undermine the security posture of downstream vendors.

Recommended Actions

  • Deploy Fortinet’s emergency patch immediately on all FortiClient installations.
  • Enforce multi‑factor authentication for VPN access pending full remediation.
  • Conduct a rapid inventory of all assets using FortiClient and verify patch compliance.
  • Review logs for anomalous authentication attempts during the window of vulnerability exposure.
  • Update third‑party risk registers to reflect the elevated supply‑chain risk from FortiClient.

Source: Dark Reading

📰 Original Source
https://www.darkreading.com/vulnerabilities-threats/fortinet-emergency-patch-forticlient-zero-day

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.