logo

CVE-2026-35616: FortiClient EMS Flaw Actively Exploited in Malware Attacks

ID: 9c6b7052-33c4-5830-a784-d04a23a6044e

STIX ID: report--9c6b7052-33c4-5830-a784-d04a23a6044e

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-05-28

Date Updated: 2026-05-29

Author: Pierluigi Paganini

...
...

A critical FortiClient EMS vulnerability (CVE-2026-35616, CVSS 9.1) permitting unauthenticated remote code execution has been actively exploited in the wild; attackers pushed a fake Fortinet update via EMS to execute PowerShell and deploy EKZ Infostealer, which harvests browser credentials and exfiltrates them over HTTP. Fortinet issued out-of-band hotfixes for affected 7.4.5/7.4.6 and plans a permanent fix in 7.4.7, and CISA added the flaw to its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.