Fortinet disclosed a critical FortiClient Endpoint Management Server flaw, CVE-2026-35616, caused by improper access control in the EMS API that lets a remote, unauthenticated attacker bypass authentication and authorization and potentially execute code or commands on the host. Fortinet and CISA said the bug is being actively exploited as a zero-day, with affected versions identified as FortiClientEMS 7.4.5 through 7.4.6; the vendor directed customers to upgrade to 7.4.7 or apply available hotfixes.
Reporting and public tooling indicate attackers have been scanning for exposed EMS instances and targeting enterprise environments including government, healthcare, and cryptocurrency organizations. Security researchers published detection guidance and an exposure-checking tool for internet-facing systems, while defenders were urged to restrict external access to EMS, review logs for suspicious API activity, and assess whether exploitation may have been paired with other recently disclosed FortiClient EMS weaknesses such as CVE-2026-21643.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
In May 2026, eSentire reported a customer intrusion in the Energy, Utilities & Waste sector where attackers exploited CVE-2026-35616 to deploy a fake Fortinet update, FortiEndpoint_Patch.exe, delivering EKZ Stealer. The report added technical details including browser credential theft, storage in C:\ProgramData\log.txt, Base64-encoded HTTP POST exfiltration to 83.138.53.110, and analysis of the malware's compiler-based obfuscation.
In May 2026, Arctic Wolf observed attackers exploiting CVE-2026-35616 to compromise FortiClient EMS and push a fake Fortinet update, FortiEndpoint_Patch.exe, to managed endpoints. The payload was identified as EKZ Infostealer, a previously unreported browser credential stealer that exfiltrated harvested data over HTTP to attacker-controlled infrastructure.
A public GitHub repository for CVE-2026-35616 checking was published by Bishop Fox, providing defenders with a way to identify potentially vulnerable or exposed FortiClient EMS instances. This represented a new technical resource following disclosure of the actively exploited flaw.
CISA added Fortinet FortiClient EMS flaw CVE-2026-35616 to its Known Exploited Vulnerabilities catalog after disclosure of active exploitation. The listing formally recognized the bug as exploited in the wild and elevated urgency for remediation.
Fortinet identified affected versions as FortiClient EMS 7.4.5 through 7.4.6 and advised customers to upgrade to 7.4.7 or later or apply relevant hotfixes. Security guidance also emphasized restricting external access and monitoring for suspicious API activity.
Fortinet disclosed CVE-2026-35616, a critical improper access control flaw in FortiClient Endpoint Management Server that can let a remote unauthenticated attacker send crafted requests leading to unauthorized code or command execution. Fortinet and CISA confirmed the bug was being actively exploited in the wild.
Exploitation of Fortinet FortiClient EMS vulnerability CVE-2026-35616 reportedly began in late March 2026, with automated scanning and attacks observed against exposed EMS systems. Reported targeting included organizations in government, healthcare, and cryptocurrency sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
esentire.com
Open sourcehelpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcegithub.com
Open sourcetheregister.com
Open sourceblog.cybernexora.com
Open sourcerunzero.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.