Live webinar · Free · 45 minutes
CVE-2026-35616 FortiClient EMS: Patch, Hunt, Harden for district and public-sector IT teams running FortiClient EMS
A working session on CVE-2026-35616 — how to confirm whether your FortiClient EMS build is in scope, get to Fortinet's fixed version, and answer the harder question of what happened during the days exploitation was observed before an advisory existed. Built for small SLED and K-12 teams who own the management server and the help desk at the same time.
- A version-first triage answeryou leave knowing whether you are in scope, using the narrow affected range in the public record: 7.4.5 and 7.4.6, with watchTowr and CyberSecurityNews both reporting that the FortiClient EMS 7.2 branch is not affected. Some attendees will find out they were never exposed, which is a legitimate outcome.
- A clear path to the fixQualys reports users must upgrade to FortiClient EMS 7.4.7 or later, and Censys notes Fortinet also published version-specific hotfix instructions for 7.4.5 and 7.4.6, linked from FG-IR-26-099. We walk the upgrade-versus-hotfix decision for a small team with one maintenance window, and why you re-read the advisory before you act.
- A patch SLA you can actually defendwe separate tier-0 management systems (EMS, RMM, MDM, patch servers) from ordinary workloads and write down an out-of-band process: who owns the box, who is authorized to take it offline at 9pm, and what the target window is.
- A hunting approach that does not depend on guessworkbecause exploitation was observed before the advisory existed, patching after the advisory landed left an unanswered question. We cover what to look for conceptually on a management server, what log retention you need to answer it at all, and when to escalate to a SOC. We do not hand out invented indicators; no authoritative IOC set surfaced in our research, so the session points you to Fortinet PSIRT and CISA for artifacts.
- A reachability review you can run the same weekUpGuard notes that because FortiClient EMS is a central endpoint management platform, compromise provides "a foothold for lateral movement" — in a district, that means movement across the network the console already reaches. We treat management-interface exposure, VPN- or ZTNA-gated admin access, and host segmentation as the durable lesson that outlives this CVE. Framed as good practice, not as a guarantee.
Reserve your seat
Free · 45 minutes · 12 seats per session
No sales sequence. One reminder before the session, and the recording after.
What we actually cover
What people bring to this session.
How do I know if I'm even affected, without reading nine vendor blogs?
We go straight to version checking against the recorded affected range, and we say plainly that the 7.2 branch is out of scope per both watchTowr and CyberSecurityNews — re-checked against FG-IR-26-099 before each session, because version ranges get revised. You get a five-minute triage sequence instead of an alert-noise problem.
We patched it. Are we done?
No, and we explain why in concrete terms: exploitation was observed March 31 per watchTowr, the advisory landed April 4, and CISA's KEV listing followed April 6. Anyone who patched after that still has a gap to account for. The session structures it as patch, verify, hunt, harden.
Why does everyone quote a different severity score?
Qualys, watchTowr and CyberSecurityNews all cite CVSS 9.1; UpGuard and SentinelOne's vulnerability database list 9.8. We show you how to handle that in your own risk register — pick one, attribute it, note the discrepancy — and why SentinelOne's listed EPSS probability of 5.95% (a 30-day model that changes daily) never overrides a confirmed KEV listing.
How do we prove the remediation actually worked to an auditor or a board?
We cover independent validation as a concept. As one example, Horizon3.ai states a NodeZero Rapid Response test is available to determine whether a FortiClient EMS deployment is exposed to CVE-2026-35616 and to validate that remediation removed exploitability. That is Horizon3's claim about their tooling, not ours, and Horizon3 is a research source here, not a palmiq partner. The broader point: this is the kind of event your flaw remediation process needs to be able to evidence, not just intend.
Before you register
Common questions
- Is this vendor-specific, or useful if we don't run FortiClient EMS?
- Most of it transfers. The triage and version-check portion is Fortinet-specific; the tier-0 patch SLA, hunting method and management-plane hardening apply to any RMM, MDM or patch server you operate.
- Will you give us detection rules and IOCs to load?
- No. Our research did not surface an authoritative indicator set for this CVE, and guessing hunting artifacts would waste your time and misdirect your search. The hunting segment is methodological, and we point you to Fortinet PSIRT and CISA for authoritative artifacts.
- The advisory is months old now. Is the guidance still current?
- Affected version ranges, fixed builds and hotfix availability are frequently revised after initial publication, and a build newer than 7.4.7 may exist by the time you attend. We re-check FG-IR-26-099 before each session and tell you what has changed.
- Who should attend from our district or agency?
- Whoever owns the EMS server and whoever can approve an out-of-band change window. Those are often two different people, and the session is more useful when both are on the call.
Rather talk it through first? Call 703-336-9700, or see the other sessions.