FortiClient EMS Flaw Sees Fresh Exploitation After April Hotfix
Attackers are still hitting a critical FortiClient EMS vulnerability that Fortinet patched — and flagged as actively exploited — months ago.

Fortinet issued hotfixes in April for a critical vulnerability in FortiClient EMS, disclosing at the time that the flaw was already being exploited in the wild. Now fresh attacks are landing on the same bug.
That gap — between patch availability and actual deployment — is where most enterprise damage happens. It is not glamorous. It is not novel. It is just painful.
Fortinet's April advisory classified the issue as zero-day exploitation at the time of disclosure, which means defenders were already behind when the fix dropped. The company urged immediate patching. Some organizations listened. Others, clearly, did not.
FortiClient EMS is an endpoint management server that handles device registration, posture checks, and policy enforcement for FortiClient endpoints. From an identity standpoint, it sits in an interesting position: it influences whether a device is trusted enough to participate in network access control decisions. Compromise here isn't just an endpoint problem — it can affect the integrity of the access decisions downstream.
Would MFA have helped? Honestly, it depends on the attack vector. If the vulnerability allows unauthenticated remote code execution at the server level, which critical-rated EMS flaws have done before, then no — MFA on user accounts wouldn't have blocked exploitation. The auth layer simply isn't what's being targeted. The server process itself is.
That distinction matters when security teams are triaging risk. Patching is the control that applies here, not credential hygiene.
The pattern is familiar: a vendor drops a hotfix with an in-the-wild exploitation warning, some portion of the install base patches within weeks, and the remainder becomes the next wave's target pool. Attackers don't need new tooling — they just need unpatched servers.
Fortinet has faced scrutiny over the past two years for a series of critical vulnerabilities across its product line, several involving authentication bypass or pre-auth RCE. The company's response cadence has generally been fast. The customer patching cadence has not always matched it.
If your organization runs FortiClient EMS and hasn't applied the April hotfix, that is the entire action item.



