Most concrete, time-sensitive assertions in the article (existence of an NHS England National CSOC cyber alert CC-4766; Fortinet PSIRT advisory FG-IR-26-099 dated 4 April 2026; affected versions 7.4.5–7.4.6; unauthenticated improper access control leading to code/command execution; hotfix guidance; and CVSS 9.1) are supported by primary sources from NHS England and Fortinet.
Most concrete, time-sensitive assertions in the article (existence of an NHS England National CSOC cyber alert CC-4766; Fortinet PSIRT advisory FG-IR-26-099 dated 4 April 2026; affected versions 7.4.5–7.4.6; unauthenticated improper access control leading to code/command execution; hotfix guidance; and CVSS 9.1) are supported by primary sources from NHS England and Fortinet. Several supporting/context claims (CISA KEV listing with a specific add date and a federal remediation deadline; Shadowserver ‘~2,000 exposed’ count; and claims about a prior CVE being actively exploited) rely on secondary reporting and/or could not be validated from primary government catalogues within this research session due to access issues, so they are marked Unverified rather than False. The narrative framing is broadly consistent with available evidence, but some details appear embellished or internally inconsistent (e.g., watchTowr text as captured includes a contradictory clause about credentials).
Medium — Confidence is medium because the highest-priority technical claims are strongly supported by primary sources (NHS England CC-4766 and Fortinet FG-IR-26-099), but several notable supporting claims (CISA KEV add date/deadline; Shadowserver exposure numbers; Tenable’s alleged 9.8 rating; and ‘no UK breaches confirmed’) could not be fully validated from primary, up-to-date sources within this session, primarily due to inability to access the CISA KEV catalogue directly and lack of direct Shadowserver primary material.
NHS England National CSOC alert CC-4766 FortiClient EMS CVE-2026-35616
Fortinet advisory FG-IR-26-099 CVE-2026-35616 FortiClient Endpoint Management Server 7.4.5 7.4.6 hotfix
CISA Known Exploited Vulnerabilities CVE-2026-35616 added 6 April 2026 remediation due 9 April 2026
WatchTowr exploitation attempts 31 March 2026 FortiClient EMS CVE-2026-35616 honeypots
Shadowserver 2000 internet-accessible FortiClient EMS instances 2,000 SecurityWeek Shadowserver FortiClient EMS
CVE-2026-21643 FortiClient EMS SQL injection actively exploited March 2026 Defused Shadowserver
Cyber Security Agency of Singapore alert AL-2026-031 CVE-2026-35616