Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

A serious, now-patched security vulnerability affecting FortiClient Endpoint Management Server (EMS) deployments is still being used by threat actors to distribute malware that steals credentials.

According to Arctic Wolf, the campaign distributed malware among controlled endpoints by abusing trusted endpoint management technology. Threat actors used PowerShell to discreetly run the malicious application while disguising the credential stealer payload as a Fortinet endpoint update.

The exploitation of CVE-2026-35616 (CVSS score: 9.1), a crucial pre-authentication API access bypass that results in privilege escalation, was detected by the cybersecurity firm in May 2026. Fortinet fixed the problem in FortiClient EMS 7.4.7 and later.

After a successful breach, the threat actor modifies a Remote Access Profile configuration and endpoint policy to introduce a malicious script for execution on endpoint devices read more about Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *