AUTO-UPDATED

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Threat actors are exploiting a critical pre-authentication vulnerability in FortiClient Endpoint Management Server to deploy credential-stealing malware by masquerading malicious payloads as legitimate software updates across managed endpoints.

Key Points

  • Cybersecurity firm Arctic Wolf identified the exploitation of CVE-2026-35616, a critical vulnerability with a CVSS score of 9.1.
  • Attackers bypass API authentication to modify EMS configurations and push malicious PowerShell scripts to all managed endpoint devices.
  • The campaign uses a fake update file, "FortiEndpoint_Patch.exe," to harvest sensitive browser data including passwords, cookies, and credit card information.
  • Fortinet addressed the security flaw in FortiClient EMS version 7.4.7 and subsequent releases.
  • Stolen data is exfiltrated to an attacker-controlled server at 83.138.53.110 via HTTP POST requests.

Why it Matters

This vulnerability allows attackers to weaponize trusted management infrastructure, turning a single server compromise into a widespread breach of all connected endpoints. The theft of session cookies and credentials poses a significant risk, as these can be used to bypass multi-factor authentication and gain unauthorized access to sensitive cloud and internal applications.
Internet Published by info@thehackernews.com (The Hacker News)
Read original