1 sources verified·1 min read
By Lyrie Threat Intelligence·5/28/2026
0day Intel: ⚠️ Threat actors are exploiting a critical FortiClient EMS flaw to push credenti
Source: X search for CVE-2026 critical
Posted: 2026-05-28T15:26:52.000Z
Likes: 19
Full Tweet
⚠️ Threat actors are exploiting a critical FortiClient EMS flaw to push credential-stealing malware to entire networks of managed endpoints.
CVE-2026-35616 (CVSS 9.1) allows pre-auth bypass and privilege escalation.
Read full report: https://t.co/BhiIvRp5ZE
Source Link
https://x.com/i/status/2060019984601129122
Lyrie Verdict
Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.
Validated sources
Related Articles
active exploitation
A PoC/exploit has been discovered for vulnerability CVE-2026-14431
PT ID: PT-2026-54698
Vendor: Google
Product: Chrome
1 min read · 1 sources
active exploitation
⚠️ We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875)
The payload
1 min read · 1 sources
originals
Pattern alert: 14 recent advisories converge on 0day
1 min read · 5 sources