- What: A certificate verification flaw in FortiClient EMS allows impersonation.
- Impact: Attackers could impersonate AD Connectors.
PSIRT Missed certificate verification in AD Connector communication with FortiClient EMS Summary An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key. Version Affected Solution FortiClientEMS 8.0 Not affected Not Applicable FortiClientEMS 7.4 7.4.3 through 7.4.5 Upgrade to 7.4.6 or above FortiClientEMS 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.6 or above FortiClientEMS 7.2 7.2 all versions Migrate to a fixed release Acknowledgement Fortinet is pleased to thank Ramn Costales de Ledesma from Telefonica de Espaa for reporting this vulnerability under responsible disclosure. Timeline 2026-07-14: Initial publication IR Number FG-IR-26-147 Published Date Jul 14, 2026 Component OTHERS Severity Medium Discovered External Attack Type Unauthenticated Known Exploited No CVSSv3 Score 6.7 Impact Information disclosure CVE ID CVE-2026-59836 Download CVRF CSAF