FortiClient EMS Vulnerability Actively Exploited by Infostealers
TL;DR. A critical FortiClient EMS vulnerability, CVE-2026-35616, is being actively exploited to deploy information-stealing malware. - Attackers use FortiClient's management pathway to deliver malicious PowerShell commands to endpoints. - The EKZ Infostealer targets major browsers to steal credentials, cookies, and autofill data. - Fortinet released hotfixes, and the flaw is on CISA's Known Exploited Vulnerabilities list.
- CVE-2026-35616, a critical FortiClient EMS vulnerability (CVSS 9.1), is under active exploitation.
- Threat actors deploy EKZ Infostealer through FortiClient's management system via PowerShell scripts.
- The malware targets popular browsers like Chrome, Edge, and Firefox for data exfiltration.
- Organizations must apply Fortinet's patches immediately to mitigate risk.
Sources
- Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks — securityweek.com
- thehackernews.com — thehackernews.com
- bleepingcomputer.com — bleepingcomputer.com