May 28, 2026
FortiClient EMS Exploit (CVE-2026-35616): What Businesses Using Fortinet Need to Do Right Now
Arctic Wolf discovered an active campaign exploiting CVE-2026-35616 in FortiClient EMS. Attackers bypass authentication, push malware to all managed endpoints, and steal browser credentials plus session cookies. Here's how to check if you're affected and what to do.
















