Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FortiClient EMS Flaw Exploited by Hackers for Data Theft

FortiClient EMS Flaw Exploited by Hackers for Data Theft

Posted on May 28, 2026 By CWS

Cybercriminals have been actively exploiting a critical vulnerability in the FortiClient Endpoint Management Server (EMS) to spread credential-stealing malware. The flaw, which has since been patched, was misused by threat actors to disguise malware as legitimate updates.

Exploitation of FortiClient EMS Vulnerability

According to Arctic Wolf, the cyberattack leverages the now-patched CVE-2026-35616 vulnerability, which scored 9.1 on the CVSS scale. This pre-authentication API access bypass allows for privilege escalation, enabling attackers to manipulate the endpoint management infrastructure deceitfully. The vulnerability was rectified in FortiClient EMS version 7.4.7 and subsequent versions.

By mimicking legitimate management operations, hackers were able to execute malicious PowerShell commands on managed endpoints. This tactic enabled them to alter configurations, delay firmware updates, and insert harmful scripts into Remote Access Profiles.

Malicious Use of PowerShell and FortiClient Tools

Arctic Wolf’s analysis reveals that the attackers used FortiClient’s management pathways to distribute malicious commands. They disguised the malware payload as FortiClient endpoint updates, executing them stealthily through PowerShell scripts.

Furthermore, the attackers leveraged a legitimate executable, “fortitray.exe,” to run a command script, which activated a Base64-encoded PowerShell command. This command was responsible for downloading and executing a malicious payload, subsequently sending data to an attacker-controlled server.

Impact and Mitigation Measures

The malware, masquerading as “FortiEndpoint_Patch.exe,” is capable of extracting sensitive information such as passwords and credit card details from web browsers. However, it lacks the ability to exfiltrate data over the network directly; this task is performed by the PowerShell script used in the attack.

Arctic Wolf warns that the exfiltrated session cookies and stored credentials could give attackers access to various online services and internal systems, bypassing multi-factor authentication in some cases. Organizations are urged to update their FortiClient EMS to the latest version and review endpoint management configurations to prevent similar intrusions.

In conclusion, the exploitation of this FortiClient EMS vulnerability underscores the need for constant vigilance in cybersecurity practices. Updating software and monitoring network activities remain crucial in defending against such sophisticated threats.

The Hacker News Tags:API bypass, credential stealer, CVE-2026-35616, Cybersecurity, data theft, endpoint security, FortiClient, Fortinet, Malware, network security, PowerShell, security patch, Vulnerability

Post navigation

Previous Post: Phishing Emails Spread VIP Keylogger Malware
Next Post: Edamame’s New System Tackles AI Code Drift

Related Posts

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild The Hacker News
Oracle Resolves Critical RCE Vulnerability in Identity Manager Oracle Resolves Critical RCE Vulnerability in Identity Manager The Hacker News
Learn How Leading Companies Secure Cloud Workloads and Infrastructure at Scale Learn How Leading Companies Secure Cloud Workloads and Infrastructure at Scale The Hacker News
FBI Warns of Rising ATM Jackpotting Losses Exceeding M FBI Warns of Rising ATM Jackpotting Losses Exceeding $20M The Hacker News
MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign The Hacker News
5 Lessons from River Island 5 Lessons from River Island The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerabilities Found in WatchGuard Agent for Windows
  • Citrix NetScaler Flaw Actively Exploited, CISA Urges Action
  • CISA Highlights Exploited Gitea Code Injection Risk
  • Apache Tomcat Patches Critical Security Vulnerabilities
  • Critical Next.js Flaws Allow Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerabilities Found in WatchGuard Agent for Windows
  • Citrix NetScaler Flaw Actively Exploited, CISA Urges Action
  • CISA Highlights Exploited Gitea Code Injection Risk
  • Apache Tomcat Patches Critical Security Vulnerabilities
  • Critical Next.js Flaws Allow Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark