FortiClient EMS Vulnerability Exploited to Distribute EKZ Infostealer Malware
Hackers exploit FortiClient EMS flaw to push infostealer malware

Image: Bleepingcomputer
Hackers are taking advantage of an authentication bypass vulnerability in FortiClient Enterprise Management Server (EMS) to deploy EKZ infostealer malware. This malware masquerades as a legitimate Fortinet update and exploits critical flaws to extract sensitive data from users' devices.
- 01The vulnerability, identified as CVE-2026-35616, allows remote attackers to execute arbitrary code without authentication.
- 02Fortinet released emergency hotfixes for affected versions 7.4.5 and 7.4.6 in response to the exploitation.
- 03The EKZ infostealer targets sensitive information from both Chromium-based and Firefox browsers, including credentials and credit card details.
- 04Indicators of exploitation include specific log entries related to certificate authentication anomalies.
- 05Cybersecurity firm Arctic Wolf provides detection guidance to help organizations mitigate these attacks.
Advertisement
In-Article Ad
Hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deploy EKZ infostealer malware. This malware is disguised as a legitimate update for Fortinet endpoints and is executed through VPN scripting workflows. The flaw allows unauthenticated remote attackers to run arbitrary code via specially crafted requests. Fortinet confirmed the exploitation in early April and issued emergency hotfixes for versions 7.4.5 and 7.4.6. Following this, the Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to secure their systems. Arctic Wolf observed that the EKZ malware targets sensitive information, including credentials and credit card data, by extracting stored data from browsers. The malware circumvents encrypted password protections, making it particularly dangerous. Researchers recommend monitoring for specific log entries that indicate exploitation attempts and suggest vigilance against suspicious administrative activities. Arctic Wolf's report includes detailed detection strategies to help organizations defend against these attacks.
Advertisement
In-Article Ad
Organizations using FortiClient EMS are at risk of data breaches due to the exploitation of this vulnerability.
Advertisement
In-Article Ad
Reader Poll
How concerned are you about vulnerabilities in enterprise management software?
Connecting to poll...
More about Fortinet
Read the original article
Visit the source for the complete story.







