Lyrie
Active Exploitation
1 sources verified·1 min read
By Lyrie Threat Intelligence·5/28/2026

0day Intel: ⚠️ Threat actors are exploiting a critical FortiClient EMS flaw to push credenti

Source: X search for CVE-2026 critical

Posted: 2026-05-28T15:26:52.000Z

Likes: 19

Full Tweet

⚠️ Threat actors are exploiting a critical FortiClient EMS flaw to push credential-stealing malware to entire networks of managed endpoints.

CVE-2026-35616 (CVSS 9.1) allows pre-auth bypass and privilege escalation.

Read full report: https://t.co/BhiIvRp5ZE

Source Link

https://x.com/i/status/2060019984601129122

Lyrie Verdict

Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.

Validated sources

  1. [1]@209811713 on X