Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEVulnerability

FortiClient EMS CVE-2026-35616: Authentication Bypass Delivers EKZ Infostealer

By ogwatermelon
May 29, 2026 4 Min Read
0
May 28, 2026

Hackers are actively exploiting a critical authentication bypass vulnerability in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer dubbed EKZ. The flaw, tracked as CVE-2026-35616, allows unauthenticated remote attackers to execute arbitrary code by abusing endpoint APIs and VPN scripting workflows. Consequently, organizations relying on FortiClient EMS for endpoint management must patch immediately and audit for signs of compromise.

What Happened: FortiClient EMS Authentication Bypass Exploited for Infostealer Deployment

CVE-2026-35616 is an improper access control vulnerability in FortiClient EMS that enables unauthenticated remote attackers to execute arbitrary code or commands via specially crafted requests. Fortinet confirmed active exploitation in early April 2026 and released emergency hotfixes for versions 7.4.5 and 7.4.6. However, attackers continue to leverage the flaw in the wild.

Earlier this month, Arctic Wolf observed intrusion campaigns abusing the vulnerability to deploy the EKZ infostealer. The attack chain begins with exploitation of endpoint APIs to perform administrative actions without authentication. The attacker then modifies EMS configuration and VPN policies to introduce malicious script execution. Moreover, the payload is disguised as a legitimate Fortinet endpoint update and executed through FortiClient-managed VPN scripting workflows.

The Shadowserver Foundation reported approximately 2,000 internet-exposed EMS instances at the time of disclosure. CISA reacted quickly by ordering federal agencies to secure their instances by the end of the disclosure week. Therefore, the window for defenders to act remains narrow.

Technical Details of the FortiClient EMS Vulnerability

The vulnerability stems from improper access control enforcement within FortiClient EMS endpoint APIs. An unauthenticated remote attacker can send specially crafted requests to perform administrative actions. This includes modifying Remote Access Profile configurations and VPN policies.

Once the attacker gains administrative control over EMS policies, they inject malicious scripts into VPN scripting workflows. Seconds after endpoints establish an IPsec tunnel to a FortiGate firewall, the legitimate fortitray.exe process launches malicious batch scripts through Command Prompt. These scripts execute a base64-encoded PowerShell payload that downloads and runs malware disguised as a Fortinet patch. The harvested data is then exfiltrated to an attacker-controlled VPS over HTTP.

The EKZ infostealer itself features standard credential-stealing functionality. It targets both Chromium-based and Firefox web browsers. The malware extracts stored credentials, credit card details, addresses, phone numbers, and cookies to text files while bypassing encrypted password protections. Therefore, compromised cookies can provide access to accounts protected by multi-factor authentication without requiring login credentials.

Key indicators of exploitation include:

  • Log entries containing “Certificate not found in request header”
  • Followed seconds later by “Certificate user: fortinet-ca2 … successfully updated”
  • Unexpected changes to Remote Access Profile configurations
  • New administrative accounts or logins from unfamiliar origins such as Tor or VPS IP addresses

Business and Operational Impact

The exploitation of CVE-2026-35616 poses significant risk to organizations using FortiClient EMS for centralized endpoint and VPN management. The attack chain is particularly dangerous because it leverages legitimate Fortinet processes and VPN infrastructure to execute malware, making detection more difficult.

Real-world consequences include:

  • Credential theft: Browser-stored passwords, credit cards, and addresses extracted at scale
  • Session hijacking: Stolen cookies bypass multi-factor authentication on cloud services and corporate applications
  • Lateral movement: Compromised credentials enable further network penetration and privilege escalation
  • Supply chain risk: Managed service providers using FortiClient EMS across multiple tenants face cascading compromise
  • Regulatory exposure: Stolen personal and financial data triggers GDPR, PCI-DSS, and state breach notification requirements

With approximately 2,000 internet-exposed EMS instances identified by The Shadowserver Foundation, the attack surface remains substantial. Organizations that have not applied emergency hotfixes should assume exposure and investigate for indicators of compromise.

Mitigation and Recommendations

Immediate Actions for Defenders

  1. Upgrade FortiClient EMS to the latest patched version immediately. Fortinet released emergency hotfixes for versions 7.4.5 and 7.4.6 in early April 2026.
  2. Audit FortiClient EMS logs for certificate-authentication anomalies, specifically entries reading “Certificate not found in request header” followed by successful certificate updates.
  3. Review Remote Access Profile configurations for unauthorized script injections or policy changes.
  4. Investigate any new administrative accounts, logins from Tor exit nodes or VPS IP addresses, or configuration changes made outside normal change windows.
  5. Force password resets and terminate active sessions for any accounts whose credentials may have been harvested by the EKZ infostealer.

Long-Term Hardening Measures

  • Reduce internet exposure of FortiClient EMS management interfaces to authorized IP ranges only
  • Implement network segmentation between EMS servers and endpoint populations
  • Enable comprehensive logging and monitoring for EMS administrative actions and VPN policy changes
  • Subscribe to Fortinet PSIRT and CISA KEV notifications for early warning of future vulnerabilities
  • Conduct regular vulnerability scans of Fortinet infrastructure and validate patch compliance

Bottom line: CVE-2026-35616 is a critical authentication bypass in FortiClient EMS that is being actively exploited to deploy the EKZ infostealer through trusted VPN workflows. Patching, log auditing, and credential rotation are immediate priorities for all affected organizations.

Incident Summary

CVE ID / Incident: CVE-2026-35616
Affected Systems: FortiClient EMS versions 7.4.5 and 7.4.6 (prior to emergency hotfix)
Disclosure Date: April 2026 (active exploitation confirmed); Arctic Wolf report published May 28, 2026
Patch Status: Emergency hotfixes available from Fortinet
CVSS Score: Critical (authentication bypass leading to remote code execution)
Estimated Exposed Instances: Approximately 2,000 internet-exposed EMS instances (per Shadowserver Foundation)

References

  1. Bill Toulas, BleepingComputer, “Hackers exploit FortiClient EMS flaw to push infostealer malware,” May 28, 2026, https://www.bleepingcomputer.com/news/security/hackers-exploit-forticlient-ems-flaw-to-push-infostealer-malware/ (accessed May 29, 2026).
  2. Arctic Wolf, “FortiClient EMS Authentication Bypass CVE-2026-35616 Exploited to Deploy EKZ Infostealer,” May 2026, https://arcticwolf.com/resources/blog/forticlient-ems-cve-2026-35616-ekz-infostealer/ (accessed May 29, 2026).
  3. CISA, “Known Exploited Vulnerabilities Catalog,” https://www.cisa.gov/known-exploited-vulnerabilities-catalog (accessed May 29, 2026).
  4. The Shadowserver Foundation, “Internet-Exposed FortiClient EMS Instances,” April 2026, https://www.shadowserver.org/ (accessed May 29, 2026).
  5. Fortinet PSIRT, “FG-IR-26-127: FortiClient EMS Authentication Bypass Vulnerability,” April 2026, https://www.fortinet.com/psirt/FG-IR-26-127 (accessed May 29, 2026).

Tags:

CVEVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

Gitea CVE: Private Container Images Exposed for Four Years

Next

Unpatched Gogs Zero-Day Enables Remote Code Execution on Git Servers

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.