---
title: "FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch"
url: https://daily.dev/posts/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patc-qobbehwip
source_url: https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch
type: article
source: "Arctic Wolf"
published: 2026-05-27T18:26:43.112Z
updated: 2026-05-27T19:41:52.899Z
tags: ["security", "malware"]
reading_time: 10
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch

**[Arctic Wolf](https://daily.dev/sources/arcticwolf)** · 10 min read · 0 upvotes · 0 comments

## Summary

Arctic Wolf Labs documented active exploitation of CVE-2026-35616, an improper access control vulnerability in Fortinet's FortiClient EMS that allows unauthenticated attackers to bypass API authentication and gain privileged access. Threat actors leveraged the management platform's own VPN scripting functionality (on_connect directives) to push malicious PowerShell commands fleet-wide to managed endpoints. The payload, disguised as a legitimate Fortinet patch named FortiEndpoint_Patch.exe, is a previously unreported credential stealer dubbed EKZ Infostealer. It extracts credentials, cookies, and autofill data from Chromium and Firefox-family browsers — including bypassing Chrome's app-bound encryption via the IElevator::DecryptData API — then exfiltrates results via HTTP POST to a threat-actor-controlled VPS. Detection guidance covers EMS log anomalies, suspicious PowerShell process trees spawned by fortitray.exe, and network indicators tied to 83.138.53.110.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch>

## Similar posts on daily.dev

- [CVE-2026-35616](https://daily.dev/posts/cve-2026-35616-nzsndgx4k) · Arctic Wolf · 0 upvotes · 0 comments
- [CVE-2026-21643: Critical SQL Injection in FortiClientEMS](https://daily.dev/posts/cve-2026-21643-critical-sql-injection-in-forticlientems-qxiu6qu9c) · Arctic Wolf · 1 upvotes · 0 comments
- [FortiBleed Campaign Harvests 110M\+ Credentials, Fuels Ransomware Operations](https://daily.dev/posts/fortibleed-campaign-harvests-110m-credentials-fuels-ransomware-operations-jiqarmttq) · Orca Security Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patc-qobbehwip)
