CVE-2026-35616: FortiClient EMS Flaw Actively Exploited in Malware AttacksSecurity Affairs·May 29, 09:02 UTC · May 29, 2026Vulnerability in the wildCVE-2026-3561660
FortiClient improper access control exposes users' VPN credentialsSecurity Affairs·Dec 14, 13:28 UTC · Dec 14, 2017Exploit / PoCCVE-2017-1418460
U.S. CISA adds a flaw in Fortinet FortiClient EMS to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 7, 09:02 UTC · Apr 7, 2026Exploit / PoC in the wildCVE-2026-3561660
Critical Fortinet FortiClient EMS flaw exploited for Remote Code ExecutionSecurity Affairs·Mar 30, 10:44 UTC · Mar 30, 2026Vulnerability in the wildCVE-2026-21643CVE-2023-4878860
Critical Fortinet FortiClient EMS bug under active attack (CVE-2026-21643)Help Net Security·Jun 24, 10:29 UTC · Jun 24, 2026Vulnerability in the wildCVE-2026-2164360
New infostealer reaches enterprise devices through FortiClient EMS vulnerabilityHelp Net Security·May 29, 00:00 UTC · May 29, 2026VulnerabilityCVE-2026-3561660
China-linked actor's malware DeepData exploits FortiClient VPN zero-daySecurity Affairs·Nov 19, 15:08 UTC · Nov 19, 2024Exploit / PoC60
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential StealerThe Hacker News·May 31, 12:13 UTC · May 31, 2026MalwareCVE-2026-3561660
Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flawHelp Net Security·May 31, 00:00 UTC · May 31, 2026Malware in the wildCVE-2026-45659CVE-2026-34926CVE-2026-3561660
FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)Help Net Security·Jun 24, 10:28 UTC · Jun 24, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-2164360
Fortinet Releases Emergency Patch After FortiClient EMS Bug Is ExploitInfosecurity Magazine·Apr 7, 09:26 UTC · Apr 7, 2026Vulnerability in the wildCVE-2026-35616CVE-2026-2164360
Fortinet Patches Actively Exploited CVE-2026The Hacker News·Apr 6, 17:04 UTC · Apr 6, 2026Vulnerability in the wildCVE-2026-35616CVE-2026-2164360
CVE-2026-35616: Fortinet fixes actively exploited highSecurity Affairs·Apr 6, 13:07 UTC · Apr 6, 2026Vulnerability in the wildCVE-2026-35616CVE-2026-2164360
CISA adds FortiClient EMS, Ivanti EPM CSA, Nice Linear eMerge E3-Series bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 25, 20:52 UTC · Mar 25, 2024Exploit / PoC in the wildCVE-2023-48788CVE-2021-44529CVE-2019-725660
Critical Fortinet's FortiClient EMS flaw actively exploited in the wildSecurity Affairs·Mar 23, 08:58 UTC · Mar 23, 2024Exploit / PoC in the wildCVE-2023-4878860
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploitedHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-21643CVE-2026-20093+2 CVEs160
Critical FortiClient EMS vulnerability fixed, (fake?) PoC for sale (CVE-2023-48788)Help Net Security·Apr 15, 08:17 UTC · Apr 15, 2024Exploit / PoC in the wildCVE-2023-4878860
Fortinet Patches Critical Bug in FortiClient EMSInfosecurity Magazine·Mar 14, 10:15 UTC · Mar 14, 2024Vulnerability in the wildCVE-2023-48788CVE-2023-42789CVE-2023-42790+2 CVEs60
Fortinet customers confront actively exploited zeroCyberScoop·Apr 6, 21:12 UTC · Apr 6, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-2164360
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and MoreThe Hacker News·Apr 6, 12:46 UTC · Apr 6, 2026Malware in the wildCVE-2026-5281CVE-2026-3502CVE-2026-35616+1 CVEs60
June 2026 CVE LandscapeRecorded Future·Jul 17, 00:00 UTC · Jul 17, 2026Ransomware in the wildCVE-2026-35616CVE-2026-25939CVE-2020-17103+53 CVEs60
April 2026 CVE LandscapeRecorded Future·Jun 3, 00:00 UTC · Jun 3, 2026Ransomware in the wildCVE-2026-33032CVE-2026-39987CVE-2009-0238+30 CVEs60
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe SoftwareThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Exploit / PoC in the wildCVE-2026-21643CVE-2020-9715CVE-2023-36424+3 CVEs60
Singapore, US warn of latest Fortinet bug being exploited in wildThe Record·Apr 6, 16:25 UTC · Apr 6, 2026Exploit / PoC in the wildCVE-2026-3561660
Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ CountriesThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2025Threat actorCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Russia-linked APT Seashell Blizzard is behind the long-running global access operation BadPilot campaignSecurity Affairs·Feb 13, 12:21 UTC · Feb 13, 2025Threat actorCVE-2021-34473CVE-2022-41352CVE-2023-32315+4 CVEs160
Subgroup of Russia’s Sandworm compromising US and European organizations, Microsoft saysThe Record·Feb 12, 18:22 UTC · Feb 12, 2025Threat actorCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access ToolsThe Hacker News·Dec 20, 06:30 UTC · Dec 20, 2024VulnerabilityCVE-2023-4878860
Hackers Exploit Fortinet Flaw, Deploy ScreenConnect, Metasploit in New CampaignThe Hacker News·Apr 18, 14:09 UTC · Apr 18, 2024Exploit / PoCCVE-2023-4878860
CISA Alerts on Active Exploitation of Flaws in Fortinet, Ivanti, and Nice ProductsThe Hacker News·Mar 28, 04:45 UTC · Mar 28, 2024Ransomware in the wildCVE-2023-48788CVE-2021-44529CVE-2019-7256+1 CVEs60
Week in review: Cybersecurity job openings, hackers use 1-day flaws to drop custom Linux malwareHelp Net Security·Mar 17, 00:00 UTC · Mar 17, 2024Malware in the wildCVE-2024-0799CVE-2024-0800CVE-2023-4878860
Cisco and Fortinet Release Security Patches for Multiple ProductsThe Hacker News·Jul 7, 11:45 UTC · Jul 7, 2022VulnerabilityCVE-2022-20812CVE-2022-20813CVE-2022-20808+4 CVEs60
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via NThe Hacker News·Aug 10, 16:38 UTC · Aug 10, 2026Ransomware in the wildCVE-2026-18577CVE-2026-18556CVE-2023-37679+7 CVEs60
FortiBleed Credential Theft Linked to INC and Lynx Ransomware OperationsThe Hacker News·Jul 2, 13:05 UTC · Jul 2, 2026RansomwareCVE-2026-3561660
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last WeekThe Hacker News·Jun 19, 13:44 UTC · Jun 19, 2026Vulnerability in the wildCVE-2026-39813CVE-2026-39808CVE-2026-25089+1 CVEs60
Fortinet Warned as Three Critical FortiSandbox Bugs Come Under AttackSecurity Affairs·Jun 16, 14:26 UTC · Jun 16, 2026Vulnerability in the wildCVE-2026-39813CVE-2026-39808CVE-2026-25089+1 CVEs60
PAN-OS GlobalProtect Authentication Bypass (CVE-2026The Hacker News·May 31, 12:13 UTC · May 31, 2026Vulnerability in the wildCVE-2026-0257CVE-2026-3561660
Security Affairs newsletter Round 572 by Pierluigi PaganiniSecurity Affairs·Apr 12, 08:34 UTC · Apr 12, 2026Ransomware in the wildCVE-2026-35616CVE-2026-2576960
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & MoreThe Hacker News·Mar 26, 15:38 UTC · Mar 26, 2026Malware in the wildCVE-2026-33017CVE-2026-2013160
Fortinet SIEM issue coincides with spike in bruteCyberScoop·Aug 13, 19:21 UTC · Aug 13, 2025Ransomware in the wildCVE-2025-25256CVE-2023-48788CVE-2024-4757560