S

EPISODE · May 28, 2026 · 0 MIN

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

from Security Stuff · host Trace3

A critical vulnerability in FortiClient Endpoint Management Server, first patched in April, is now being actively exploited to deploy information-stealing malware disguised as a fake Fortinet security update. The flaw, which carries a CVSS score of nine point one and requires no authentication, allows attackers to execute malicious PowerShell commands through FortiClient's own management system, enabling them to steal browser credentials and data from every managed endpoint. CISA has added the vulnerability to its Known Exploited Vulnerabilities list, and organizations are urged to apply Fortinet's patches immediately.

Episode metadata supplied by the publisher feed · Published May 28, 2026

Embed this episode

NOW PLAYING

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

0:00 0:41

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security Stuff?

This episode is 0 minutes long.

When was this Security Stuff episode published?

This episode was published on May 28, 2026.

Can I download this Security Stuff episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!