logo

Hackers exploit FortiClient EMS flaw to push infostealer malware

ID: aefd8edf-bab1-59f0-acae-6a117803b9d1

STIX ID: report--aefd8edf-bab1-59f0-acae-6a117803b9d1

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Bill Toulas

...
...

Attackers are actively exploiting CVE-2026-35616 in FortiClient EMS to push an EKZ infostealer by abusing unauthenticated endpoint APIs and VPN scripting workflows; the payload runs via fortitray/Command Prompt and PowerShell, harvests browser-stored credentials, cards, and cookies, and exfiltrates data to an attacker-controlled VPS. Fortinet released emergency hotfixes, CISA ordered federal mitigations, and observers reported thousands of exposed EMS instances, with detection guidance noting log strings like "Certificate not found in request header."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.