🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Fortinet FortiClient EMS Authentication Bypass RCE (CVE-2026-35616) | MSSP Advisory

High🔴 KEV ALERTConfirmed
DateMay 28, 2026
CVECVE-2026-35616
CVSS Score9.8
Affectedforticlientems
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
Attackers are exploiting CVE-2026-35616, an authentication bypass flaw in FortiClient Enterprise Management Server (EMS), to deploy EKZ credential stealer malware. The vulnerability allows remote code execution without authentication on affected EMS instances. FortiClient EMS manages endpoint security clients across enterprise networks.
⚠️Why It Matters for MSSPs
Your own FortiClient EMS deployment becomes a direct entry point into your infrastructure and every client network you manage from it. Client environments running FortiClient with compromised EMS servers face credential theft that bypasses their endpoint protection, creating liability exposure when you knew about this flaw but said nothing.
Recommended Action
Immediately update all FortiClient EMS instances to the latest patched version and verify no unauthorized access occurred in server logs within the past 30 days.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.