Hackers are actively exploiting a critical FortiClient EMS flaw to deploy infostealer malware on vulnerable systems. Security researchers warned that attackers are abusing the enterprise management platform to push malicious payloads directly to managed endpoints.

The attacks show how cybercriminals increasingly target centralized management infrastructure to compromise large numbers of devices at once.

Critical Vulnerability Enables Unauthorized Access

The attacks rely on CVE-2026-35616, a critical authentication bypass vulnerability affecting FortiClient Enterprise Management Server. Researchers said the flaw allows attackers to execute unauthorized commands through specially crafted requests.

Fortinet confirmed that threat actors are already exploiting the vulnerability in real-world attacks.

The flaw affects FortiClient EMS versions 7.4.5 and 7.4.6. Fortinet released security updates and urged customers to patch exposed servers immediately.

Because EMS platforms manage endpoint deployments and security policies, attackers can use compromised servers to distribute malware across enterprise environments.

Attackers Push EKZ Infostealer Malware

Researchers observed attackers using the FortiClient EMS flaw to deploy a previously undocumented malware strain called EKZ infostealer. The malware disguised itself as a legitimate Fortinet update to avoid suspicion.

The attackers reportedly abused EMS scripting functionality to execute malicious PowerShell commands on managed systems.

Once installed, EKZ attempted to steal browser-stored credentials and other sensitive information from infected devices. Researchers said the malware transmitted stolen data back to attacker-controlled infrastructure.

The campaign highlights the risks associated with trusted management platforms. If attackers gain control over those systems, they can distribute malware internally without triggering immediate suspicion.

Organizations Urged to Patch Immediately

Security teams should prioritize patching vulnerable EMS servers and review logs for unusual administrative activity. Researchers also advised organizations to inspect endpoint systems for unauthorized scripts or suspicious software deployments.

Experts recommend limiting external exposure of management servers whenever possible. Companies should also reset potentially compromised credentials if they suspect successful exploitation.

Endpoint management infrastructure remains a valuable target for cybercriminals because it often provides privileged access across large corporate environments.

Conclusion

The FortiClient EMS flaw demonstrates how dangerous vulnerabilities in enterprise management platforms can become. Attackers used the flaw to distribute credential-stealing malware through trusted infrastructure, increasing the risk of large-scale compromise. Organizations should patch affected systems quickly and monitor for signs of unauthorized activity before attackers expand exploitation efforts.


0 responses to “FortiClient EMS Flaw Exploited to Deploy Malware”