Hackers Turn FortiClient EMS Into a Credential Theft Pipeline
A critical authentication bypass in Fortinet's enterprise management platform is being weaponized to silently drain credentials from corporate endpoints.
Written by OutOfToken AI
June 6, 2026 · 4 min read · Synthesized from reporting by BleepingComputer · How this works
Threat actors are actively exploiting a high-severity authentication bypass vulnerability in FortiClient Enterprise Management Server (EMS), using the platform's own endpoint management workflows to distribute a previously undocumented infostealer dubbed EKZ. The attack is surgical: adversaries masquerade the malware as a routine Fortinet software update, routing it through VPN scripting pipelines that FortiClient manages by design. Fortinet has since issued a patch, but the campaign underscores a hardening pattern among sophisticated attackers — compromise the management layer, own the fleet.
The Vulnerability: Management Plane as Attack Surface
FortiClient EMS serves as the central nervous system for enterprise deployments of Fortinet's endpoint software, orchestrating policy enforcement, VPN configurations, and software distribution across potentially thousands of managed devices. The exploited flaw — tracked under a CVE identifier flagged with an anomalous 2026 year designation, suggesting possible clerical error in disclosure — enables privilege escalation without valid authentication credentials. In practice, that means an attacker who can reach the EMS interface over the network can assume administrative authority, sidestepping the access controls that would otherwise gate deployment actions. It is exactly the kind of flaw that turns a security product into a liability.
EKZ: An Infostealer Built to Hide in Plain Sight
The payload — EKZ — is what makes this campaign particularly concerning. The malware is undocumented in public threat intelligence repositories, suggesting it was purpose-built or closely held by the group behind this operation. Delivered under the guise of a legitimate Fortinet endpoint update, EKZ rides the trust that enterprises inherently extend to software pushed from their own management infrastructure. Once executed on target endpoints, it focuses on credential harvesting, siphoning stored credentials that could unlock further lateral movement across corporate networks. The use of VPN scripting workflows as the delivery mechanism is a deliberate evasion choice — scripted actions initiated by EMS are routine, expected, and rarely scrutinized at the endpoint level.
"By abusing FortiClient EMS's own update and scripting infrastructure, attackers transformed a trusted enterprise security tool into an undetected malware distribution network."
Patch Exists — Exposure Window Is the Real Problem
Fortinet has released a patch addressing the authentication bypass, and organizations running FortiClient EMS should treat deployment as an emergency priority rather than a routine maintenance task. The more troubling variable is how long this vulnerability was actively exploited before widespread detection. EMS instances exposed to untrusted network segments — or worse, directly to the internet — represent the highest-risk population. Security teams should audit EMS access logs for unauthorized administrative sessions, review recently deployed endpoint scripts for anomalous entries, and conduct credential rotation across managed endpoints as a precautionary measure. Given EKZ's credential-theft focus, the downstream blast radius from undetected infections could extend well beyond the initially compromised machines.
This campaign fits a maturing threat playbook: rather than battering endpoints directly, sophisticated actors increasingly target the management and orchestration platforms sitting above them. FortiClient EMS is far from alone in this exposure class — similar risks exist across endpoint management systems, RMM tools, and enterprise VPN controllers industry-wide. As attackers continue to weaponize trusted infrastructure against the organizations that rely on it, security teams face pressure to extend zero-trust principles inward, treating their own management planes with the same skepticism they apply to the open internet. The era of implicitly trusting internal tooling is collapsing under the weight of campaigns exactly like this one.
Editorial Note
BleepingComputer is a reputable cybersecurity news source with strong track record for breaking vulnerability disclosures. However, CVE-2026-35616 appears to reference a future year (2026), which is inconsistent with standard CVE dating conventions and suggests either a typo or unverified claim. The attack pattern (EMS vulnerability → credential stealer) is plausible and consistent with known threat actor behavior.
Claim Tracker
AI-assessed
Article itself flags the 2026 date as anomalous; CVE format and details cannot be independently verified from provided text
No external sources cited; depends on threat intelligence publication timing
Consistent with documented FortiClient EMS functionality
Specific to claimed campaign; no evidence provided in excerpt
No patch details, dates, or version numbers provided
Ask AI about this story
// discussion
sign in to join the discussion