Signal
Critical FortiClient EMS vulnerability exploited to deliver credential stealer malware
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-05-28 12:55 UTCUpdated 2026-05-28 17:25 UTC
rss
cveexploitsmalwareincident_responsesecurity_advisory
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.3 top sources shown
Overview
A critical authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) is actively exploited by threat actors to deploy an undocumented credential stealer named EKZ.
Score total
1.31
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
- Active exploitation observed despite patches released in April 2026.
- Threat actors continue to abuse trusted infrastructure, increasing attack stealth and impact.
- Organizations using FortiClient EMS must urgently apply updates to mitigate ongoing risks.
Why it matters
- The vulnerability enables attackers to bypass authentication and deploy malware within trusted management infrastructure.
- Credential stealer malware compromises sensitive user data and facilitates further attacks.
- Immediate patching is critical to prevent widespread exploitation across managed endpoints.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- Threat actors exploit a critical authentication bypass vulnerability (CVE-2026-35616) in FortiClient EMS to deliver credential stealer malware.
How sources frame it
- Multiple Cybersecurity News Sources: neutral
Consolidated multiple reports to highlight ongoing exploitation and urgent patching needs for FortiClient EMS vulnerability.
All evidence
All evidence
Hackers exploit FortiClient EMS flaw to push infostealer malware
bleepingcomputer_all · bleepingcomputer.com · 2026-05-28 17:25 UTC
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
thehackernews · thehackernews.com · 2026-05-28 15:26 UTC
Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks
SecurityWeek · securityweek.com · 2026-05-28 12:55 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 3
Top publishers (this list)
- bleepingcomputer_all (1)
- thehackernews (1)
- SecurityWeek (1)
Top origin domains (this list)
- bleepingcomputer.com (1)
- thehackernews.com (1)
- securityweek.com (1)