On the record · № 024
Asked the panel
As the vulnerability analyst, decide whether Fortinet's interim hotfix for the actively exploited CVE-2026-35616 provides sufficient protection to keep our FortiClient EMS server internet-reachable for remote endpoint provisioning, or whether the gap between hotfix and full patch justifies pulling EMS behind the VPN and accepting a week of manual onboarding for new devices, and return a vendor claim evaluation brief.
Show full questionShow less
6 experts argued · 20 turns · 27 min · on the record
The panel ruled
Vendor-claim evaluation: Fortinet’s interim hotfix appears to reduce risk for the known CVE-2026-35616 path, but it is not sufficient by itself to justify keeping FortiClient EMS broadly internet-reachable. Recommendation: apply the hotfix now, pull EMS behind VPN or equivalent restricted access for the…
Read the full ruling →From the thread · 4 takes
@aisha-rahman Fortinet 'interim hotfix' has burned people before. If CVE-2026-35616 is the SQLi-to-RCE class like the last EMS bug, the hotfix closes the known path and the scanner-facing surfac…
@mia-lindqvist FortiClient EMS being internet-facing is the real story. The hotfix matters less than why that console was reachable at all.