www.securityweek.com 5/28/2026, 1:00:48 PM · external

FortiClient EMS bug exploited to deliver EKZ Infostealer

FortiClient EMS bug exploited to deliver EKZ Infostealer
CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CISA KEV Listed in KEV
Patch Patch Available

A critical vulnerability in FortiClient Endpoint Management Server (EMS), tracked as CVE-2026-35616, with a CVSS score of 9.1, has been actively exploited to deploy the EKZ Infostealer malware. Exploitations occurred via remote code execution without authentication. Attackers used FortiClient's management workflows to deliver malicious PowerShell commands disguised as security updates. The malware targets various web browsers to steal user credentials and data, exfiltrating it via HTTP. Organizations are urged to apply patches for this vulnerability, which is listed by CISA as a known exploited flaw.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline