Briefing

Fortinet FortiClient EMS flaw used to push credential‑stealing malware

security
by [email protected] (The Hacker News) ·

Patch FortiClient EMS immediately to stop credential-stealing attacks.

What to do now

Apply FortiClient EMS patch immediately.

Summary

In early April, attackers exploited a critical authentication‑bypass flaw (CVE‑2026‑35616) in Fortinet’s FortiClient Enterprise Management Server (EMS) versions 7.4.5 and 7.4.6 to deliver a sophisticated credential‑stealing malware called EKZ. The exploit allows unauthenticated remote attackers to execute arbitrary code on the EMS, which then modifies VPN policies and configuration settings to trigger malicious scripts. The malware is disguised as a legitimate Fortinet endpoint update and is delivered through the VPN scripting workflows that the FortiClient normally uses, enabling it to run silently on affected endpoints. EKZ harvests browser credentials, bypasses multi‑factor authentication, and exfiltrates stolen data to an attacker‑controlled virtual private server over plain HTTP.

Fortinet issued emergency hotfixes in the first week of April, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered all federal agencies to patch their EMS instances by the end of that week. Shadowserver reported that 2,000 EMS instances were exposed to the vulnerability at the time of the alert. Arctic Wolf Security identified a key indicator of compromise: certificate‑authentication anomalies such as “Certificate not found in request header,” which can help defenders detect ongoing exploitation attempts. The attack’s use of Fortinet’s own VPN scripting to deliver the payload makes it appear as a legitimate update, thereby bypassing many traditional endpoint protection mechanisms.

The incident underscores the importance of promptly applying vendor‑issued patches and conducting thorough audits of VPN policies to prevent unauthorized script execution. Security teams are advised to monitor logs for certificate‑authentication anomalies, verify that no unexpected scripts are being executed, and ensure that all EMS instances are updated to the latest patched version. The potential for MFA bypass and large‑scale credential theft poses a significant risk to organizations that rely on FortiClient EMS for endpoint management, especially within federal agencies that were specifically targeted by the CISA directive.

Key changes

  • FortiClient EMS flaw used to deliver credential-stealing malware
  • Attackers disguised payload as legitimate Fortinet update
  • Vulnerability was patched earlier but remains exploited
  • Fortinet released patch closing the vulnerability and blocking malicious updates
  • Administrators should install the latest EMS patch and monitor for unauthorized updates

Affects

internal

Source angles · 2 perspectives

The Hacker News
Independent angle

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Open
Bleeping Computer
Independent angle

Hackers Exploit FortiClient EMS Flaw to Push Infostealer Malware

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting