Security researchers report that threat actors are exploiting a critical vulnerability in FortiClient Enterprise Management Server (EMS) to distribute credential-stealing malware to managed endpoints. Multiple outlets describe the activity as a campaign that abuses the trusted endpoint management workflow to push an infostealer payload across devices under FortiClient EMS control.
The reported issue centers on an authentication bypass/improper access control flaw identified as CVE-2026-35616. One report says attackers disguise the malicious component as a Fortinet endpoint update, while another notes that the payload is executed through FortiClient-managed VPN scripting workflows. Researchers attribute the findings to Arctic Wolf, which characterizes the approach as leveraging endpoint management infrastructure to deliver the payload to otherwise managed and reachable systems.
Bleeping Computer refers to an undocumented credential stealer named EKZ, while other reporting focuses on the general capability and delivery method rather than broader campaign details. The flaw is described as now patched, but the reports indicate active exploitation attempts while the vulnerable EMS configuration remains unremediated.