FortiClient EMS CVE-2026-35616: Authentication Bypass Delivers EKZ Infostealer
Hackers are actively exploiting a critical authentication bypass vulnerability in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer dubbed EKZ. The flaw, tracked as CVE-2026-35616, allows unauthenticated remote attackers to execute arbitrary code by abusing endpoint APIs and VPN scripting workflows. Consequently, organizations relying on FortiClient EMS for endpoint management must patch immediately and audit for signs of compromise.
What Happened: FortiClient EMS Authentication Bypass Exploited for Infostealer Deployment
CVE-2026-35616 is an improper access control vulnerability in FortiClient EMS that enables unauthenticated remote attackers to execute arbitrary code or commands via specially crafted requests. Fortinet confirmed active exploitation in early April 2026 and released emergency hotfixes for versions 7.4.5 and 7.4.6. However, attackers continue to leverage the flaw in the wild.
Earlier this month, Arctic Wolf observed intrusion campaigns abusing the vulnerability to deploy the EKZ infostealer. The attack chain begins with exploitation of endpoint APIs to perform administrative actions without authentication. The attacker then modifies EMS configuration and VPN policies to introduce malicious script execution. Moreover, the payload is disguised as a legitimate Fortinet endpoint update and executed through FortiClient-managed VPN scripting workflows.
The Shadowserver Foundation reported approximately 2,000 internet-exposed EMS instances at the time of disclosure. CISA reacted quickly by ordering federal agencies to secure their instances by the end of the disclosure week. Therefore, the window for defenders to act remains narrow.
Technical Details of the FortiClient EMS Vulnerability
The vulnerability stems from improper access control enforcement within FortiClient EMS endpoint APIs. An unauthenticated remote attacker can send specially crafted requests to perform administrative actions. This includes modifying Remote Access Profile configurations and VPN policies.
Once the attacker gains administrative control over EMS policies, they inject malicious scripts into VPN scripting workflows. Seconds after endpoints establish an IPsec tunnel to a FortiGate firewall, the legitimate fortitray.exe process launches malicious batch scripts through Command Prompt. These scripts execute a base64-encoded PowerShell payload that downloads and runs malware disguised as a Fortinet patch. The harvested data is then exfiltrated to an attacker-controlled VPS over HTTP.
The EKZ infostealer itself features standard credential-stealing functionality. It targets both Chromium-based and Firefox web browsers. The malware extracts stored credentials, credit card details, addresses, phone numbers, and cookies to text files while bypassing encrypted password protections. Therefore, compromised cookies can provide access to accounts protected by multi-factor authentication without requiring login credentials.
Key indicators of exploitation include:
- Log entries containing “Certificate not found in request header”
- Followed seconds later by “Certificate user: fortinet-ca2 … successfully updated”
- Unexpected changes to Remote Access Profile configurations
- New administrative accounts or logins from unfamiliar origins such as Tor or VPS IP addresses
Business and Operational Impact
The exploitation of CVE-2026-35616 poses significant risk to organizations using FortiClient EMS for centralized endpoint and VPN management. The attack chain is particularly dangerous because it leverages legitimate Fortinet processes and VPN infrastructure to execute malware, making detection more difficult.
Real-world consequences include:
- Credential theft: Browser-stored passwords, credit cards, and addresses extracted at scale
- Session hijacking: Stolen cookies bypass multi-factor authentication on cloud services and corporate applications
- Lateral movement: Compromised credentials enable further network penetration and privilege escalation
- Supply chain risk: Managed service providers using FortiClient EMS across multiple tenants face cascading compromise
- Regulatory exposure: Stolen personal and financial data triggers GDPR, PCI-DSS, and state breach notification requirements
With approximately 2,000 internet-exposed EMS instances identified by The Shadowserver Foundation, the attack surface remains substantial. Organizations that have not applied emergency hotfixes should assume exposure and investigate for indicators of compromise.
Mitigation and Recommendations
Immediate Actions for Defenders
- Upgrade FortiClient EMS to the latest patched version immediately. Fortinet released emergency hotfixes for versions 7.4.5 and 7.4.6 in early April 2026.
- Audit FortiClient EMS logs for certificate-authentication anomalies, specifically entries reading “Certificate not found in request header” followed by successful certificate updates.
- Review Remote Access Profile configurations for unauthorized script injections or policy changes.
- Investigate any new administrative accounts, logins from Tor exit nodes or VPS IP addresses, or configuration changes made outside normal change windows.
- Force password resets and terminate active sessions for any accounts whose credentials may have been harvested by the EKZ infostealer.
Long-Term Hardening Measures
- Reduce internet exposure of FortiClient EMS management interfaces to authorized IP ranges only
- Implement network segmentation between EMS servers and endpoint populations
- Enable comprehensive logging and monitoring for EMS administrative actions and VPN policy changes
- Subscribe to Fortinet PSIRT and CISA KEV notifications for early warning of future vulnerabilities
- Conduct regular vulnerability scans of Fortinet infrastructure and validate patch compliance
Bottom line: CVE-2026-35616 is a critical authentication bypass in FortiClient EMS that is being actively exploited to deploy the EKZ infostealer through trusted VPN workflows. Patching, log auditing, and credential rotation are immediate priorities for all affected organizations.
Incident Summary
| CVE ID / Incident: | CVE-2026-35616 |
| Affected Systems: | FortiClient EMS versions 7.4.5 and 7.4.6 (prior to emergency hotfix) |
| Disclosure Date: | April 2026 (active exploitation confirmed); Arctic Wolf report published May 28, 2026 |
| Patch Status: | Emergency hotfixes available from Fortinet |
| CVSS Score: | Critical (authentication bypass leading to remote code execution) |
| Estimated Exposed Instances: | Approximately 2,000 internet-exposed EMS instances (per Shadowserver Foundation) |
References
- Bill Toulas, BleepingComputer, “Hackers exploit FortiClient EMS flaw to push infostealer malware,” May 28, 2026, https://www.bleepingcomputer.com/news/security/hackers-exploit-forticlient-ems-flaw-to-push-infostealer-malware/ (accessed May 29, 2026).
- Arctic Wolf, “FortiClient EMS Authentication Bypass CVE-2026-35616 Exploited to Deploy EKZ Infostealer,” May 2026, https://arcticwolf.com/resources/blog/forticlient-ems-cve-2026-35616-ekz-infostealer/ (accessed May 29, 2026).
- CISA, “Known Exploited Vulnerabilities Catalog,” https://www.cisa.gov/known-exploited-vulnerabilities-catalog (accessed May 29, 2026).
- The Shadowserver Foundation, “Internet-Exposed FortiClient EMS Instances,” April 2026, https://www.shadowserver.org/ (accessed May 29, 2026).
- Fortinet PSIRT, “FG-IR-26-127: FortiClient EMS Authentication Bypass Vulnerability,” April 2026, https://www.fortinet.com/psirt/FG-IR-26-127 (accessed May 29, 2026).