securityaffairs.com 5/28/2026, 4:31:46 PM · external

FortiClient EMS flaw used to deploy EKZ Infostealer via fake patch

FortiClient EMS flaw used to deploy EKZ Infostealer via fake patch
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

A critical vulnerability in FortiClient EMS, tracked as CVE-2026-35616 with a CVSS score of 9.1, has been exploited in recent malware attacks. The flaw allows remote code execution (RCE) without authentication and enables attackers to bypass access controls. Arctic Wolf reported the exploitation of this flaw to deploy EKZ Infostealer malware, disguised as a Fortinet patch, which steals credentials. Fortinet released patches in April, and the U.S.

Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog, urging users to apply the hotfixes as soon as possible.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline