PoC Archive PoC Archive

tag

FortiClient-EMS

  • CVE-2026-35616 network CRITICAL 9.1 KEV EPSS 89%

    Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)

    CVE-2026-35616 is a pre-authentication bypass in Fortinet FortiClient EMS's certificate-chain authentication handler (certchainauth.py), which trusts the X-SSL-CLIENT-VERIFY header directly without performing real cryptographic validation of the presented…

    Patched 2026-07-03