Threat actors are exploiting a critical pre-authentication vulnerability in FortiClient Endpoint Management Server to deploy credential-stealing malware by masquerading malicious payloads as legitimate software updates across managed endpoints.
Key Points
- Cybersecurity firm Arctic Wolf identified the exploitation of CVE-2026-35616, a critical vulnerability with a CVSS score of 9.1.
- Attackers bypass API authentication to modify EMS configurations and push malicious PowerShell scripts to all managed endpoint devices.
- The campaign uses a fake update file, "FortiEndpoint_Patch.exe," to harvest sensitive browser data including passwords, cookies, and credit card information.
- Fortinet addressed the security flaw in FortiClient EMS version 7.4.7 and subsequent releases.
- Stolen data is exfiltrated to an attacker-controlled server at 83.138.53.110 via HTTP POST requests.