Back to all lessons
Awareness Lessons
5 months ago

Critical Authentication Bypass in FortiClient EMS Enables Infostealer Deployment

Attackers exploited CVE-2026-35616, a critical authentication bypass vulnerability in Fortinet's FortiClient Enterprise Management Server, to deploy EKZ infostealer malware. The attack leveraged improper access controls combined with VPN scripting workflows to execute malicious payloads disguised as legitimate software updates. This demonstrates how authentication flaws in enterprise management platforms can provide attackers with privileged access to deploy malware across managed endpoints. The incident highlights the critical importance of rapidly patching vulnerabilities in network security appliances that have elevated access to corporate infrastructure.

Tactical Insight

Immediate actions

  • Apply Fortinet's emergency hotfixes immediately to all FortiClient EMS installations
  • Review VPN scripting workflows and disable unnecessary automated update mechanisms
  • Scan managed endpoints for EKZ infostealer indicators of compromise

Long-term improvements

  • Implement automated vulnerability scanning specifically for network security appliances
  • Establish emergency patching procedures with defined SLAs for critical infrastructure components
  • Deploy network segmentation to isolate management servers from production networks

Detection measures

  • Enable detailed logging on all enterprise management platforms and VPN gateways
  • Monitor for unusual software deployment activities or unauthorized script executions
  • Implement behavioral analysis to detect credential harvesting activities on endpoints