Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Vulnerability

FortiClient EMS CVE-2026-35616 exploitation and stealer delivery

Updated 28.05.2026 20:25
Case score 56
Members 2 First seen 05.04.2026 21:45 Latest activity 28.05.2026 20:25

Overview

**FortiClient EMS** exploitation around **CVE-2026-35616** has moved from critical flaw disclosure into observed abuse of endpoint-management infrastructure to push a disguised credential stealer across managed devices. Attackers used the pre-authentication access bypass to gain privileged control over EMS settings and launch a PowerShell-based chain through trusted Fortinet processes, with stolen browser data sent to **83.138.53[.]110**. **Fortinet** issued fixes for affected **7.4.5** and **7.4.6** deployments and directs customers to **7.4.7 or later**, while the vulnerability is also listed in **CISA KEV**. Available exposure tracking found more than **2,000** internet-accessible EMS instances online, so patching needs to be paired with compromise review rather than treated as a routine update.
Latest development Open development history 3 earlier developments Fortinet confirms CVE-2026-35616 active exploitation Fortinet confirms that CVE-2026-35616 is actively exploited in the wild, credits Defused with finding a pre-authentication API access bypass in FortiClient EMS, and notes that Shadowserver found more than 2,000 exposed EMS instances online, mostly in the USA and Germany. Defused says the flaw was observed as a zero-day earlier this week before responsible disclosure to Fortinet.
  1. Earlier development

    FortiClient EMS CVE-2026-35616 exploitation wave

    By **May 2026**, attackers were using a patched **FortiClient EMS** flaw to push malicious scripts through the product's management path. The early phase centered on abusing EMS controls to reach every managed endpoint from a privileged context.

  2. Earlier development

    FortiClient EMS pre-auth API access bypass (CVE-2026-35616)

    Attackers were already abusing **CVE-2026-35616** against **FortiClient EMS** in **May 2026**. The flaw provided **pre-auth API access bypass** and **privilege escalation** before remediation in **7.4.7 and later**.

  3. Earlier development

    Fortinet issues emergency hotfix for CVE-2026-35616

    Fortinet releases an emergency hotfix for CVE-2026-35616, an improper access control flaw in FortiClient EMS 7.4.5 and 7.4.6 that can let unauthenticated attackers execute code or commands via specially crafted requests. Fortinet says FortiClient EMS 7.4.7 will also fix the issue and urges customers to install the hotfix immediately.

Signals

Impact signals
Exploitation
CVEs/products
Remediation
Threat context
Data exposure

Malware & tooling context

1 families · 3 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Exploitation Wave FortiClient EMS CVE-2026-35616 exploitation wave
Updated 28.05.2026 18:26 Lead Contribution 56
Exploitation Active Exploitation CVSS 9.1 Critical Patch Patch Available

**CVE-2026-35616** exploitation in **FortiClient Enterprise Management Server (EMS)** is being used to deliver the undocumented credential stealer **EKZ**. Attackers are abusing unauthenticated API access and **FortiClient-managed VPN scripting workflows** to disguise the payload as a **Fortinet endpoint update**, launch malicious scripts through **fortitray.exe** and **cmd.exe**, and exfiltrate stolen data to an attacker-controlled **VPS over HTTP**. **Fortinet** released emergency hotfixes for **7.4.5** and **7.4.6**, **CISA** ordered federal agencies to secure affected instances, and **The Shadowserver Foundation** reported **2,000 internet-exposed EMS instances**.

Vulnerability FortiClient EMS improper access control flaw (CVE-2026-35616)
Updated 05.04.2026 21:45 Context
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Passwords CVSS 9.8 Critical 1 more in details
All signals
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Passwords CVSS 9.8 Critical Patch Patch Available

**CVE-2026-35616** is an **actively exploited** improper access control flaw in **FortiClient Enterprise Management Server (EMS)** that lets unauthenticated attackers execute code or commands via specially crafted requests. In **May 2026**, **Arctic Wolf** observed attacks abusing EMS management paths to modify configuration and deliver **EKZ**, an undocumented credential stealer, through **FortiClient-managed VPN scripting workflows**. The payload was disguised as a **Fortinet endpoint update**, launched through **fortitray.exe** and **cmd.exe**, and used **PowerShell** to exfiltrate browser data to an attacker-controlled **VPS over HTTP**. **Fortinet** released emergency hotfixes for **7.4.5** and **7.4.6**, and later addressed the flaw in **FortiClient EMS 7.4.7 and later**.