FortiClient EMS Zero-Day: When the Control Plane Becomes Initial Access by Lucie Cardiet
ID: 8db2f4c6-4985-520a-85de-5e437a2c6fb6
STIX ID: report--8db2f4c6-4985-520a-85de-5e437a2c6fb6
Feed Name: Vectra AI Blog
**CVE-2026-35616 — FortiClient EMS control-plane compromise**: The report explains a critical zero-day in FortiClient EMS that permits unauthenticated API access leading to remote code execution; because EMS centrally manages endpoints, successful exploitation grants attackers broad, trusted reach into environments. The write-up stresses that activity from a compromised EMS blends into normal administrative telemetry across identity, network, and endpoint domains, making early detection and containment especially challenging and recommending behavior-continuity detection across domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
