INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

FortiClient EMS Flaw Exploited in Malware Attacks

| 2026-05-28 17:25 CRITICAL HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
The FortiClient EMS authentication bypass vulnerability, CVE-2026-35616, has been exploited by hackers to deliver an undocumented credential stealer called EKZ. This critical flaw allows threat actors to exploit remote code execution (RCE) and does not require authentication, posing a significant risk to organizations with unpatched systems. The vulnerability was first reported in early April, prompting Fortinet to release emergency hotfixes for versions 7.4.5 and 7.4.6 of the product. Researchers recommend defenders look for certificate-authentication anomalies and unexpected changes to Remote Access Profile configurations as red flags for suspicious administrative activity.
Technical Mitigations AI-generated
* Implement secure configuration changes: Regularly review and update Remote Access Profile configurations to ensure they do not introduce new vulnerabilities or create potential entry points for attackers. * Monitor VPN scripting workflows: Continuously monitor FortiClient-managed VPN scripting workflows to detect any suspicious activity, such as unusual API calls or modifications to EMS configuration. * Use secure patch management practices: Ensure that all patches and updates are applied securely using automated tools, rather than relying on manual scripts or user-initiated downloads. * Implement endpoint hardening measures: Implement measures to limit the privileges of FortiClient components running on endpoints, such as disabling unnecessary services or limiting access to sensitive data. * Regularly update and patch Fortinet products: Keep all Fortinet products up-to-date with the latest security patches and updates to ensure that known vulnerabilities are addressed.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

fo•••••.exe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-35616CVE-2026-35616
Target & Sectors
Global Scope
Incident Timeline
‎2026/05/28
Threat actors exploited a FortiClient EMS flaw to push infostealer malware.
organisation FortiClient Enterprise Management
organisation EMS
organisation EKZ
organisation CVE-2026
organisation CVSS
organisation FortiClient EMS
organisation FortiClient Endpoint Management
infrastructure 7.4.5
infrastructure 7.4.6
infrastructure Fortigate
organisation IPsec
organisation FortiGate
organisation Command Prompt
organisation FortiClient
organisation VPS
organisation Fortinet
organisation Remote Access
organisation Tor
organisation VPS IP
infrastructure 7.4.7
organisation API
organisation EKZ Infostealer
organisation FortiClient EMS 7.4.5
organisation SecurityAffairs
‎May 2026
Threat actors exploited a vulnerability in FortiClient EMS to push infostealer malware.
Tactical Metrics
Metrics
infrastructure
‎7.4.5
Software Version
Metrics
infrastructure
‎7.4.6
Software Version
Metrics
infrastructure
‎Fortigate
Affected Product
Metrics
infrastructure
‎7.4.7
Software Version
Intelligence Sources