---
schema: 1
kind: threat
title: FortiClient EMS CVE-2026-35616 actively exploited to push EKZ Infostealer through trusted endpoint-management channel
headline: FortiClient EMS CVE-2026-35616 actively exploited to push EKZ Infostealer through trusted endpoint-management channel
summary: "Arctic Wolf documents active ITW exploitation of CVE-2026-35616 (Fortinet FortiClient EMS 7.4.5–7.4.6, CVSS 9.1, CISA KEV since 2026-04-06). The pre-auth X-SSL-CLIENT-VERIFY header bypass is being abused to push the EKZ Infostealer to managed endpoints as a fake FortiEndpoint_Patch.exe signed under the legitimate fortitray.exe parent. Anything on 7.4.5/7.4.6 must move to 7.4.7 immediately; managed endpoints need browser-profile-write hunts."
discovered_at: "2026-05-29T05:00:01Z"
event_date: 2026-04-06
run_id: 2026-05-29-c7f56b00
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - auth-bypass
  - cisa-kev
  - infostealer
  - supply-chain
regions:
  - europe
  - switzerland
  - global
sectors:
  - public-sector
  - finance
  - energy
  - telco
entities: []
cves:
  - id: CVE-2026-35616
    cvss: "9.1"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/"
    publisher: Arctic Wolf — EKZ Infostealer campaign
    role: primary
  - url: "https://fortiguard.fortinet.com/psirt/FG-IR-26-099"
    publisher: Fortinet PSIRT FG-IR-26-099
    role: corroborating
  - url: "https://thehackernews.com/2026/05/threat-actors-exploit-critical.html"
    publisher: "The Hacker News, 2026-05-28"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Arctic Wolf Labs published technical evidence on 2026-05-27 of an in-the-wild campaign abusing CVE-2026-35616, the CWE-284 improper-access-control flaw in Fortinet FortiClient EMS 7.4.5 and 7.4.6 (CVSS 9.1; on CISA KEV since 2026-04-06)."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-29.md
---

Arctic Wolf Labs published technical evidence on 2026-05-27 of an [in-the-wild campaign abusing CVE-2026-35616](https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/), the [CWE-284 improper-access-control flaw in Fortinet FortiClient EMS 7.4.5 and 7.4.6](https://fortiguard.fortinet.com/psirt/FG-IR-26-099) (CVSS 9.1; on [CISA KEV since 2026-04-06](https://nvd.nist.gov/vuln/detail/CVE-2026-35616)). The vulnerable code path trusts the `X-SSL-CLIENT-VERIFY` HTTP header set by a fronting reverse proxy or load balancer instead of validating client-certificate state itself; an unauthenticated attacker on the network spoofs the header to reach privileged management APIs. In the observed campaign, attackers modify Remote Access Profile configurations to push a PowerShell payload signed under the trusted `fortitray.exe` binary that fetches `FortiEndpoint_Patch.exe` — actually the EKZ Infostealer. EKZ copies itself into Chromium/Gecko browser-profile directories (Chrome, Microsoft Edge, Firefox, LibreWolf, Waterfox, Pale Moon, Thunderbird) to clear elevation-validation checks, then dumps encrypted credential and cookie stores via `nss3.dll`. Compromise of a single EMS server cascades to every managed endpoint. Patch is FortiClient EMS 7.4.7.

**Why it matters to us:** FortiClient EMS is widely deployed across Swiss federal and cantonal network-security estates and across EU public-sector networks. Deep-dive treatment in § 5 below.
