Zero-dayApr 6, 2026
Fortinet Issues Emergency Patch for FortiClient Zero-Day
Fortinet releases emergency patch for FortiClient authentication bypass zero-day CVE-2026-35616.
Vendor Watch
Run Fortinet?
Get an email when a reviewed story names Fortinet, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Fortinet has issued an emergency patch for CVE-2026-35616, an authentication bypass vulnerability in FortiClient that has been actively exploited in the wild. This zero-day represents the latest in a growing series of Fortinet vulnerabilities targeted by threat actors. Organizations running affected FortiClient versions should prioritize patching immediately.
Indicators of Compromise
- cve — CVE-2026-35616
Entities
Fortinet (vendor)FortiClient (product)