logo

FortiClient EMS Zero-Day: When the Control Plane Becomes Initial Access by Lucie Cardiet

ID: 8db2f4c6-4985-520a-85de-5e437a2c6fb6

STIX ID: report--8db2f4c6-4985-520a-85de-5e437a2c6fb6

Feed Name: Vectra AI Blog

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-05-01

...
...

**CVE-2026-35616 — FortiClient EMS control-plane compromise**: The report explains a critical zero-day in FortiClient EMS that permits unauthenticated API access leading to remote code execution; because EMS centrally manages endpoints, successful exploitation grants attackers broad, trusted reach into environments. The write-up stresses that activity from a compromised EMS blends into normal administrative telemetry across identity, network, and endpoint domains, making early detection and containment especially challenging and recommending behavior-continuity detection across domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.