Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Vulnerability

FortiClient EMS CVE-2026-35616 exploitation and stealer delivery

Updated 28.05.2026 20:25
Case score 56
Case score 56 Members 2 Latest activity 28.05.2026 20:25
Active exploitation Patch available CVSS: 9.8 Critical
Members 2 First seen 05.04.2026 21:45 Last seen 28.05.2026 18:26 Updated 28.05.2026 20:25

Overview

**FortiClient EMS** exploitation around **CVE-2026-35616** has moved from critical flaw disclosure into observed abuse of endpoint-management infrastructure to push a disguised credential stealer across managed devices. Attackers used the pre-authentication access bypass to gain privileged control over EMS settings and launch a PowerShell-based chain through trusted Fortinet processes, with stolen browser data sent to **83.138.53[.]110**. **Fortinet** issued fixes for affected **7.4.5** and **7.4.6** deployments and directs customers to **7.4.7 or later**, while the vulnerability is also listed in **CISA KEV**. Available exposure tracking found more than **2,000** internet-accessible EMS instances online, so patching needs to be paired with compromise review rather than treated as a routine update.

Signals

8 derived
Exploitation
Exploitation Active exploitation CVSS
CVEs/products
CVE
Victims/regions
Victim region Germany Victim region United States
Remediation
Remediation Patch available
Threat context
Tooling
Data exposure
Data Passwords

Malware context

1 families · 3 tools
Tools
cmd.exe fortitray.exe PowerShell

Member happenings

2 related
Exploitation Wave FortiClient EMS CVE-2026-35616 exploitation wave
Updated 28.05.2026 18:26 Lead Contribution 56
Exploitation Active Exploitation CVSS 9.1 Critical Patch Patch Available

**CVE-2026-35616** exploitation in **FortiClient Enterprise Management Server (EMS)** is being used to deliver the undocumented credential stealer **EKZ**. Attackers are abusing unauthenticated API access and **FortiClient-managed VPN scripting workflows** to disguise the payload as a **Fortinet endpoint update**, launch malicious scripts through **fortitray.exe** and **cmd.exe**, and exfiltrate stolen data to an attacker-controlled **VPS over HTTP**. **Fortinet** released emergency hotfixes for **7.4.5** and **7.4.6**, **CISA** ordered federal agencies to secure affected instances, and **The Shadowserver Foundation** reported **2,000 internet-exposed EMS instances**.

Vulnerability FortiClient EMS improper access control flaw (CVE-2026-35616)
Updated 05.04.2026 21:45 Context
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Passwords CVSS 9.8 Critical +1

**CVE-2026-35616** is an **actively exploited** improper access control flaw in **FortiClient Enterprise Management Server (EMS)** that lets unauthenticated attackers execute code or commands via specially crafted requests. In **May 2026**, **Arctic Wolf** observed attacks abusing EMS management paths to modify configuration and deliver **EKZ**, an undocumented credential stealer, through **FortiClient-managed VPN scripting workflows**. The payload was disguised as a **Fortinet endpoint update**, launched through **fortitray.exe** and **cmd.exe**, and used **PowerShell** to exfiltrate browser data to an attacker-controlled **VPS over HTTP**. **Fortinet** released emergency hotfixes for **7.4.5** and **7.4.6**, and later addressed the flaw in **FortiClient EMS 7.4.7 and later**.