CISA Mandates Urgent Patch for Fortinet EMS Vulnerability Amid Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for federal agencies to patch a critical vulnerability in FortiClient Enterprise Management Server (EMS) by April 9. The flaw, identified as CVE-2026-35616, allows attackers to bypass authentication controls, posing significant risks to federal networks. Discovered by cybersecurity firm Defused, the vulnerability has been actively exploited in the wild. Fortinet has released emergency hotfixes to address the issue, urging immediate action from IT administrators. CISA's directive, part of Binding Operational Directive 22-01, emphasizes the urgency of securing federal systems against this threat.