Affected Systems
Fortinet FortiClient Enterprise Management Server (EMS). Specific vulnerable versions not provided in available data. Authentication bypass vulnerability CVE-2026-35616 allows unauthorized access.
Exploitation Status
Active exploitation confirmed. Threat actors deploying EKZ credential stealer malware through this vulnerability in the wild.
Business Impact
Organizations running FortiClient EMS face immediate risk of credential theft and unauthorized network access. EMS typically manages endpoint security for enterprise deployments, making compromise high-impact. Attackers can bypass authentication to gain control and deploy malware for credential harvesting. Specific CVSS score not yet published.
Urgency
🔴 Immediate
Recommended Actions
- Immediately identify all FortiClient EMS instances in your environment and isolate them from internet access if possible
- Check Fortinet security advisories for CVE-2026-35616 patch availability and apply updates immediately
- Review FortiClient EMS logs for unauthorized authentication attempts or anomalous administrative activity
- Hunt for indicators of EKZ malware on endpoints managed by FortiClient EMS, focusing on credential access patterns
- Implement network segmentation to limit EMS server exposure and enforce strict access controls until patched
