Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FortiClient EMS Flaw Exploited by Hackers for Data Theft

FortiClient EMS Flaw Exploited by Hackers for Data Theft

Posted on May 28, 2026 By CWS

Cybercriminals have been actively exploiting a critical vulnerability in the FortiClient Endpoint Management Server (EMS) to spread credential-stealing malware. The flaw, which has since been patched, was misused by threat actors to disguise malware as legitimate updates.

Exploitation of FortiClient EMS Vulnerability

According to Arctic Wolf, the cyberattack leverages the now-patched CVE-2026-35616 vulnerability, which scored 9.1 on the CVSS scale. This pre-authentication API access bypass allows for privilege escalation, enabling attackers to manipulate the endpoint management infrastructure deceitfully. The vulnerability was rectified in FortiClient EMS version 7.4.7 and subsequent versions.

By mimicking legitimate management operations, hackers were able to execute malicious PowerShell commands on managed endpoints. This tactic enabled them to alter configurations, delay firmware updates, and insert harmful scripts into Remote Access Profiles.

Malicious Use of PowerShell and FortiClient Tools

Arctic Wolf’s analysis reveals that the attackers used FortiClient’s management pathways to distribute malicious commands. They disguised the malware payload as FortiClient endpoint updates, executing them stealthily through PowerShell scripts.

Furthermore, the attackers leveraged a legitimate executable, “fortitray.exe,” to run a command script, which activated a Base64-encoded PowerShell command. This command was responsible for downloading and executing a malicious payload, subsequently sending data to an attacker-controlled server.

Impact and Mitigation Measures

The malware, masquerading as “FortiEndpoint_Patch.exe,” is capable of extracting sensitive information such as passwords and credit card details from web browsers. However, it lacks the ability to exfiltrate data over the network directly; this task is performed by the PowerShell script used in the attack.

Arctic Wolf warns that the exfiltrated session cookies and stored credentials could give attackers access to various online services and internal systems, bypassing multi-factor authentication in some cases. Organizations are urged to update their FortiClient EMS to the latest version and review endpoint management configurations to prevent similar intrusions.

In conclusion, the exploitation of this FortiClient EMS vulnerability underscores the need for constant vigilance in cybersecurity practices. Updating software and monitoring network activities remain crucial in defending against such sophisticated threats.

The Hacker News Tags:API bypass, credential stealer, CVE-2026-35616, Cybersecurity, data theft, endpoint security, FortiClient, Fortinet, Malware, network security, PowerShell, security patch, Vulnerability

Post navigation

Previous Post: Phishing Emails Spread VIP Keylogger Malware
Next Post: Edamame’s New System Tackles AI Code Drift

Related Posts

Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan The Hacker News
How Ineffective Triage Heightens Business Risks How Ineffective Triage Heightens Business Risks The Hacker News
CPUID Breach: STX RAT Spread via Compromised Downloads CPUID Breach: STX RAT Spread via Compromised Downloads The Hacker News
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages The Hacker News
Adobe Reader Zero-Day Exploit Targets Users Since Late 2025 Adobe Reader Zero-Day Exploit Targets Users Since Late 2025 The Hacker News
TeamPCP Exploits Cloud Vulnerabilities for Cybercrime TeamPCP Exploits Cloud Vulnerabilities for Cybercrime The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Edamame’s New System Tackles AI Code Drift
  • FortiClient EMS Flaw Exploited by Hackers for Data Theft
  • Phishing Emails Spread VIP Keylogger Malware
  • IBM and Red Hat Invest $5 Billion to Enhance Open Source Security
  • Cybersecurity Threats Intensify with New Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Edamame’s New System Tackles AI Code Drift
  • FortiClient EMS Flaw Exploited by Hackers for Data Theft
  • Phishing Emails Spread VIP Keylogger Malware
  • IBM and Red Hat Invest $5 Billion to Enhance Open Source Security
  • Cybersecurity Threats Intensify with New Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark