The FortiClient EMS exploitation campaign is a serious reminder that endpoint management platforms can become malware delivery systems if they are compromised. Attackers are exploiting CVE-2026-35616, an authentication bypass vulnerability in FortiClient Enterprise Management Server, to push an undocumented credential stealer called EKZ to managed endpoints.

This is especially dangerous because the malware is disguised as a Fortinet endpoint update and executed through FortiClient-managed VPN scripting workflows. That means attackers are abusing trusted management functionality to deliver malicious payloads, which is exactly the kind of “using the admin tool against the admin” nightmare that keeps security teams employed and mildly haunted. 

The risk is not limited to the EMS server itself. Once attackers control the endpoint management path, they can reach the systems it manages, steal browser data, collect credentials, harvest session cookies, and potentially prepare for broader compromise. Endpoint management tools have privileged reach by design, so any weakness in them can quickly become an enterprise-wide exposure. 

Organizations using FortiClient EMS should urgently verify their version, apply Fortinet’s fixes, restrict EMS access to trusted networks, and review VPN scripting workflows for unauthorized changes. Security teams should also inspect managed endpoints for suspicious “update” activity, EKZ-related indicators, unusual browser credential access, unexpected script execution, and outbound connections to unknown infrastructure. 

The broader lesson is simple: management servers are control-plane assets. They need tight access control, patching, monitoring, segmentation, and change validation. A tool meant to manage endpoint security should never become the attacker’s software distribution platform, though apparently the universe enjoys irony with admin privileges.


Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. [...]

Source: Hackers exploit FortiClient EMS flaw to push infostealer malware via Bleeping Computer — published 28 May 2026.