Fortinet's Own Infrastructure Turned Against Its Users
A critical pre-authentication flaw in FortiClient EMS is letting attackers weaponize endpoint management tools to silently harvest credentials across entire corporate networks.
Written by OutOfToken AI
June 6, 2026 · 4 min read · Synthesized from reporting by The Hacker News · How this works
Attackers are exploiting a now-patched but still widely unaddressed vulnerability in Fortinet's FortiClient Endpoint Management Server to push credential-stealing malware directly through the infrastructure organizations trust to secure their endpoints. The flaw, tracked as CVE-2026-35616 with a CVSS score of 9.1, requires no authentication to exploit — giving threat actors a clean entry point into environments that may manage thousands of corporate devices. Arctic Wolf's threat intelligence team confirmed active exploitation in May 2026, and the campaign's sophistication signals this is no opportunistic smash-and-grab.
A 9.1 That Needs No Password
CVE-2026-35616 is a pre-authentication API vulnerability in FortiClient EMS — meaning an attacker positioned to reach the management server needs zero valid credentials to begin their assault. The flaw enables authentication bypass combined with privilege escalation, a pairing that effectively hands over the keys to the kingdom. Fortinet patched the vulnerability in FortiClient EMS version 7.4.7, but the window between patch release and enterprise deployment is precisely where campaigns like this one thrive. Organizations running earlier versions remain exposed, and given how slowly patch cycles move in large managed environments, that population is not trivial.
Trusted Infrastructure as a Delivery Vehicle
What distinguishes this campaign from a generic exploit-and-drop operation is its deliberate abuse of legitimate management channels. Arctic Wolf found that attackers disguised the credential-stealing payload as a legitimate Fortinet endpoint update — exploiting the implicit trust that managed devices extend to their EMS server. Once the malicious package was pushed through the compromised management plane, it propagated across the full fleet of managed endpoints without triggering the skepticism that an external download might provoke. This supply-chain-adjacent technique transforms the victim's own security tooling into a malware distribution network, making detection significantly harder for defenders relying on behavioral baselines tied to normal EMS traffic.
""The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints — threat actors disguised the credential stealer payload as a Fortinet endpoint update." — Arctic Wolf"
Credential Theft at Scale Means the Damage Compounds
The payload's focus on credential harvesting rather than immediate ransomware deployment reflects a calculated, multi-stage attack philosophy. Stolen credentials from managed enterprise endpoints — domain accounts, VPN tokens, SSO sessions — become currency for follow-on intrusions, lateral movement, and eventual data exfiltration or extortion. An EMS deployment by definition touches a broad surface area; attackers who successfully push malware through it don't get one machine's credentials, they get a harvest from the entire managed estate. Security teams should treat any confirmed exploitation of this vulnerability not as a contained incident but as a potential full-environment compromise requiring credential rotation across all affected endpoints.
The FortiClient EMS campaign is a pointed reminder that endpoint management platforms — precisely because they operate with elevated trust and broad reach — represent high-value targets for sophisticated threat actors. Patching to version 7.4.7 is non-negotiable, but organizations also need to audit EMS access logs for anomalous API calls, verify the integrity of any recently pushed endpoint packages, and treat credential compromise as the baseline assumption until proven otherwise. As attackers increasingly target the tools defenders rely on, the security of security infrastructure can no longer be an afterthought.
Editorial Note
FortiClient EMS vulnerabilities have been documented by Fortinet and tracked by security researchers. Arctic Wolf is a reputable security firm known for threat intelligence reporting. The Hacker News is an established cybersecurity news source with generally reliable reporting, though the summary appears truncated and lacks specific CVE details, patch dates, or campaign attribution specifics that would enable full verification.
Claim Tracker
AI-assessed
Future date (2026) is anachronistic; cannot verify without access to official CVE database
Described as pre-authentication API vulnerability but specific technical details not independently confirmed in excerpt
Future date inconsistency; attribution to Arctic Wolf not verified in provided text
Specific version number claim not independently verified in excerpt
Technical capabilities described but not independently verified
Ask AI about this story
// discussion
sign in to join the discussion
