INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
FortiClient EMS Flaw Exploited in Malware Attacks
| 2026-05-28 17:25 CRITICAL HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
The FortiClient EMS authentication bypass vulnerability, CVE-2026-35616, has been exploited by hackers to deliver an undocumented credential stealer called EKZ. This critical flaw allows threat actors to exploit remote code execution (RCE) and does not require authentication, posing a significant risk to organizations with unpatched systems. The vulnerability was first reported in early April, prompting Fortinet to release emergency hotfixes for versions 7.4.5 and 7.4.6 of the product. Researchers recommend defenders look for certificate-authentication anomalies and unexpected changes to Remote Access Profile configurations as red flags for suspicious administrative activity.
Technical Mitigations AI-generated
* Implement secure configuration changes: Regularly review and update Remote Access Profile configurations to ensure they do not introduce new vulnerabilities or create potential entry points for attackers.
* Monitor VPN scripting workflows: Continuously monitor FortiClient-managed VPN scripting workflows to detect any suspicious activity, such as unusual API calls or modifications to EMS configuration.
* Use secure patch management practices: Ensure that all patches and updates are applied securely using automated tools, rather than relying on manual scripts or user-initiated downloads.
* Implement endpoint hardening measures: Implement measures to limit the privileges of FortiClient components running on endpoints, such as disabling unnecessary services or limiting access to sensitive data.
* Regularly update and patch Fortinet products: Keep all Fortinet products up-to-date with the latest security patches and updates to ensure that known vulnerabilities are addressed.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
fo•••••.exe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-35616CVE-2026-35616
Target & Sectors
Global Scope
Incident Timeline
2026/05/28
Threat actors exploited a FortiClient EMS flaw to push infostealer malware.
Click on any entity below to view its context and source!
organisation
FortiClient Enterprise Management
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
organisation
EMS
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
FortiClient EMS Flaw Actively Exploited in Malware Attacks
A critical FortiClient Endpoint Management Server (EMS) vulnerability patched in April has been exploited in fresh attacks to deploy information-stealing malware, Arctic Wolf reports.
organisation
EKZ
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
organisation
CVE-2026
CVE-2026-35616:
organisation
CVSS
The flaw, tracked as
CVE-2026-35616
(CVSS score of 9.1), can be exploited remotely via crafted requests for remote code execution (RCE) and does not require authentication.
organisation
FortiClient EMS
Threat actors are exploiting a critical FortiClient EMS flaw, tracked as CVE-2026-35616, to deploy malware on unpatched systems.
Hackers exploit FortiClient EMS flaw to push infostealer malware.
organisation
FortiClient Endpoint Management
FortiClient EMS Flaw Actively Exploited in Malware Attacks
A critical FortiClient Endpoint Management Server (EMS) vulnerability patched in April has been exploited in fresh attacks to deploy information-stealing malware, Arctic Wolf reports.
infrastructure
7.4.5
Fortinet
confirmed
in early April that it was being exploited and released emergency hotfixes for versions 7.4.5 and 7.4.6 of the product.
infrastructure
7.4.6
Fortinet
confirmed
in early April that it was being exploited and released emergency hotfixes for versions 7.4.5 and 7.4.6 of the product.
infrastructure
Fortigate
Seconds after endpoints established an IPsec tunnel to a FortiGate firewall, the legitimate fortitray.exe launched malicious batch scripts through Command Prompt.
organisation
IPsec
Seconds after endpoints established an IPsec tunnel to a FortiGate firewall, the legitimate fortitray.exe launched malicious batch scripts through Command Prompt.
organisation
FortiGate
Seconds after endpoints established an IPsec tunnel to a FortiGate firewall, the legitimate fortitray.exe launched malicious batch scripts through Command Prompt.
organisation
Command Prompt
Seconds after endpoints established an IPsec tunnel to a FortiGate firewall, the legitimate fortitray.exe launched malicious batch scripts through Command Prompt.
organisation
FortiClient
The attacker disguised the malware as an update for Fortinet endpoints and executed it through VPN scripting workflows managed by FortiClient.
Researchers believe threat actors abused FortiClient’s own management features to push malicious PowerShell commands to managed endpoints, turning every connected device into a potential target.
organisation
VPS
Those scripts executed a base64-encoded PowerShell payload that downloaded and ran malware disguised as a Fortinet patch, then exfiltrated data to an attacker-controlled VPS over HTTP.
organisation
Fortinet
Malicious PowerShell code
Source: Arctic Wolf
“Rather than relying on a generic malware lure, the payload was presented as a Fortinet endpoint update and executed through FortiClient-managed VPN scripting workflows,” reads the
report from Arctic Wolf
.
“Threat actors disguised the credential stealer payload as a Fortinet endpoint update, silently executing the malicious executable through PowerShell.”
organisation
Remote Access
In lab tests, the error was followed in seconds by another entry: Certificate user: fortinet-ca2 … successfully updated
As such, the researchers recommend defenders look for certificate-authentication anomalies and unexpected changes to Remote Access Profile configurations.
organisation
Tor
Any suspicious administrative activity, such as new accounts, logins with an unfamiliar origin (Tor, VPS IP addresses), or actions leading to configuration changes, should be considered red flags.
organisation
VPS IP
Any suspicious administrative activity, such as new accounts, logins with an unfamiliar origin (Tor, VPS IP addresses), or actions leading to configuration changes, should be considered red flags.
infrastructure
7.4.7
A permanent fix will also be included in version 7.4.7.
organisation
API
The flaw is an improper access control issue that allows attackers to bypass authentication through an API and escalate privileges, posing a serious risk to affected systems.
organisation
EKZ Infostealer
Attackers used a fake Fortinet patch that actually delivered a credential-stealing malware named EKZ Infostealer.
organisation
FortiClient EMS 7.4.5
Fortinet confirmed active exploitation of the flaw and urges users of FortiClient EMS 7.4.5 and 7.4.6 to install available hotfixes.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, FortiClient)
May 2026
Threat actors exploited a vulnerability in FortiClient EMS to push infostealer malware.
Tactical Metrics
Metrics
infrastructure
7.4.5
Software Version
Click for context!
Fortinet
confirmed
in early April that it was being exploited and released emergency hotfixes for versions 7.4.5 and 7.4.6 of the product.
Metrics
infrastructure
7.4.6
Software Version
Fortinet
confirmed
in early April that it was being exploited and released emergency hotfixes for versions 7.4.5 and 7.4.6 of the product.
Metrics
infrastructure
Fortigate
Affected Product
Seconds after endpoints established an IPsec tunnel to a FortiGate firewall, the legitimate fortitray.exe launched malicious batch scripts through Command Prompt.
Metrics
infrastructure
7.4.7
Software Version
A permanent fix will also be included in version 7.4.7.
Intelligence Sources
BleepingComputer
2026-05-28
Hackers exploit FortiClient EMS flaw to push infostealer malware
BleepingComputer
Security Affairs
2026-05-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
FortiClient Enterprise Management
entity
4x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
4x
attribution
Attributing Entity
The Shadowserver Foundation
authority
3x
infrastructure
Software Version
7.4.5
version
2x
timeline
Temporal Reference
7.4.7
date
Contextual Telemetry
Context Block
7 METRICS
vulnerability
Exploited CVE
CVE-2026-35616
cve
infrastructure
Affected Product
Fortigate
software
general metric
Exposed Ems Instances
2,000
exposed ems instances
general metric
Surfaces
6
surfaces
vulnerability
CVSS Score
9
score
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
Cve-2026
35,616
cve-2026
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.