Signal

Critical FortiClient EMS vulnerability exploited to deliver credential stealer malware

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-28 12:55 UTCUpdated 2026-05-28 17:25 UTC
rss
cveexploitsmalwareincident_responsesecurity_advisory
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Hackers exploit FortiClient EMS flaw to push infostealer malware
bleepingcomputer_all · News · bleepingcomputer.com · 2026-05-28 17:25 UTC
Overview

A critical authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) is actively exploited by threat actors to deploy an undocumented credential stealer named EKZ.

Entities
FortinetFortiClient EMS
Score total
1.31
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • Active exploitation observed despite patches released in April 2026.
  • Threat actors continue to abuse trusted infrastructure, increasing attack stealth and impact.
  • Organizations using FortiClient EMS must urgently apply updates to mitigate ongoing risks.
Why it matters
  • The vulnerability allows attackers to bypass authentication and deploy malware within trusted management infrastructure.
  • Credential stealer malware compromises sensitive user data and facilitates further attacks.
  • Immediate patching is critical to prevent widespread exploitation across managed endpoints.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Threat actors exploit FortiClient EMS authentication bypass vulnerability to deploy credential stealer malware.
How sources frame it
  • BleepingComputer: neutral
Consolidated multiple reports into a clear narrative emphasizing the criticality and ongoing exploitation of the FortiClient EMS vulnerability.
All evidence
All evidence
Hackers exploit FortiClient EMS flaw to push infostealer malware
bleepingcomputer_all · bleepingcomputer.com · 2026-05-28 17:25 UTC
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
thehackernews · thehackernews.com · 2026-05-28 15:26 UTC
Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks
SecurityWeek · securityweek.com · 2026-05-28 12:55 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
  • bleepingcomputer_all (1)
  • thehackernews (1)
  • SecurityWeek (1)
Top origin domains (this list)
  • bleepingcomputer.com (1)
  • thehackernews.com (1)
  • securityweek.com (1)