CVEsupply chainremediationsmall businessFortinet
CVE-2026-35616: Your Security Tool Just Installed Malware on Every Device
Attackers exploited FortiClient EMS to push a credential stealer disguised as a Fortinet firmware update. Your endpoint management system delivered the malware for them. You can't make this up.
May 29, 2026