Shared from twixb · securityweek.com

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

securityweek.com·May 28, 2026

A critical vulnerability in FortiClient Endpoint Management Server (EMS), tracked as CVE-2026-35616, has been exploited in attacks to deploy information-stealing malware, prompting cybersecurity experts to urge immediate patching. The flaw, which allows remote code execution without authentication, has led to the EKZ Infostealer being disguised as a legitimate Fortinet patch, targeting managed endpoints.

A critical vulnerability in FortiClient Endpoint Management Server (CVE-2026-35616) is being actively exploited to deploy information-stealing malware. As a professional in cybersecurity, it's crucial to immediately apply Fortinet's patches for this flaw to prevent attackers from executing remote code on managed endpoints and exfiltrating sensitive data. Additionally, review and secure FortiClient-managed VPN scripting workflows to mitigate potential malicious use.

Powered by twixb

Want more content like this?

twixb tracks your favorite blogs and social media, filters by keywords, and delivers personalized key learnings — straight to your inbox.

More from Cybersecurity News

Recent stories curated alongside this one.