WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) Vulnerability Notification - Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

TLP:CLEAR

Author: Chase Snow

Created: Friday, May 29, 2026 - 10:13

Categories: Cybersecurity, Security Preparedness

ACTION MAY BE REQUIRED for utilities using Fortinet FortiClient Endpoint Management Server (EMS). Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.

Summary: Recent reporting from Arctic Wolf identified threat actors actively exploiting a critical improper access control vulnerability affecting Fortinet FortiClient EMS. Tracked as CVE-2026-35616 (CVSS 9.1), the vulnerability allows an unauthorized attacker to bypass API authentication and authorization controls and execute unauthorized code or commands through crafted requests.

WaterISAC added this vulnerability to its Weekly Vulnerabilities to Prioritize post on April 9.

Analyst Note: Arctic Wolf noted threat actors are exploiting the vulnerability to abuse FortiClient EMS management functionality and distribute a credential-stealing malware being called “EKZ Infostealer” across managed endpoints. The malware was disguised as a legitimate Fortinet endpoint update and deployed through trusted EMS workflows, allowing attackers to leverage the organization’s own endpoint management infrastructure to spread malicious code.

Fortinet has released hotfixes for affected versions and notes that FortiClient EMS 7.4.7 and later versions remediate the vulnerability. FortiClient EMS 7.2 is not affected. Fortinet Cloud and FortiSASE customers do not need to take action.

Affected Versions:

  • FortiClient EMS 7.4.5 – install hotfix by following these instructions.
  • FortiClient EMS 7.4.6 – install hotfix by following these instructions.

WaterISAC strongly encourages members to review Fortinet’s advisory, determine whether FortiCloud EMS is deployed within their environment, and upgrade affected systems immediately.

Additional Reading:

  • Fortinet PSIRT Advisory FG-IR-26-099
  • FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 11, 2026)

Jun 11, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – June 11, 2026

Jun 11, 2026 in Cybersecurity
Members Only

(TLP:GREEN) FBI Report – Elevated Cyber Risk to Utility Providers Supporting FIFA World Cup 2026 Tournament Events

Jun 11, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar