Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Vulnerability

FortiClient EMS CVE-2026-35616 exploitation and stealer delivery

Updated 28.05.2026 20:25
Case score 56
Case score 56 Members 2 Latest activity 28.05.2026 20:25 Active exploitation Patch available CVSS: 9.8 Critical
Active exploitation Patch available CVSS: 9.8 Critical
Members 2 First seen 05.04.2026 21:45 Last seen 28.05.2026 18:26 Updated 28.05.2026 20:25

Overview

**FortiClient EMS** exploitation around **CVE-2026-35616** has moved from critical flaw disclosure into observed abuse of endpoint-management infrastructure to push a disguised credential stealer across managed devices. Attackers used the pre-authentication access bypass to gain privileged control over EMS settings and launch a PowerShell-based chain through trusted Fortinet processes, with stolen browser data sent to **83.138.53[.]110**. **Fortinet** issued fixes for affected **7.4.5** and **7.4.6** deployments and directs customers to **7.4.7 or later**, while the vulnerability is also listed in **CISA KEV**. Available exposure tracking found more than **2,000** internet-accessible EMS instances online, so patching needs to be paired with compromise review rather than treated as a routine update.