FortiClient EMS Vulnerability Actively Exploited by Infostealers

TL;DR. A critical FortiClient EMS vulnerability, CVE-2026-35616, is being actively exploited to deploy information-stealing malware. - Attackers use FortiClient's management pathway to deliver malicious PowerShell commands to endpoints. - The EKZ Infostealer targets major browsers to steal credentials, cookies, and autofill data. - Fortinet released hotfixes, and the flaw is on CISA's Known Exploited Vulnerabilities list.

Sources

Back to QLANKR News