FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)

2026-04-04T14:51:51Z5c1580d18849214429af60931bdf168bcb4f9162238744734363068906f03ac7
APERIONAnthropicCVE-2026-20093CVE-2026-35616CiscoClaude CodeEuropean Commission breachFortiClient EMSFortinetIMCLiteLLMMicrosoft Agent GovernanceSecure BootShinyHuntersSmartFlowTeamPCPTrivyauthentication bypasscertificate expirationhotfixmalwareon-prem AI governancesource leaksupply chain attackzero-day

What happened

This feed highlights multiple high-risk incidents and mitigations: a Fortinet FortiClient EMS zero-day (CVE-2026-35616) is being exploited in the wild and Fortinet has issued emergency hotfixes for EMS 7.4.5 and 7.4.6; Cisco fixed an IMC authentication bypass (CVE-2026-20093) that could allow unauthenticated attackers to gain Admin access. Other notable items include Microsoft adding Secure Boot certificate status indicators ahead of 2026 certificate expirations, an Anthropic Claude Code source leak used as a malware lure, a Trivy-related supply-chain compromise that enabled a European Council

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
5c1580d18849214429af60931bdf168bcb4f9162238744734363068906f03ac7
Enrichment time
2026-04-04T14:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.