A critical vulnerability in FortiClient EMS has been exploited in recent attacks, prompting urgent patching efforts. The security defect, which was addressed by Fortinet through hotfixes in April, had been exploited as a zero-day vulnerability, highlighting the need for swift action to mitigate potential threats. The fact that the vulnerability has been exploited in the wild as a zero-day1 indicates a high level of risk, and organizations using FortiClient EMS should assess their exposure and apply the necessary patches immediately. The exploitation of this vulnerability demonstrates that attackers are actively targeting Fortinet products, emphasizing the importance of timely patching to prevent potential breaches. The window for patching is rapidly closing, making it essential for organizations to take immediate action to protect themselves from these attacks. So what matters most to security practitioners is that they must assess their exposure and patch their systems without delay to prevent falling victim to these exploits.