<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #FortiClient EMS</title><description>Cybersecurity articles tagged #FortiClient EMS on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Lynx Ransomware Linked to Massive FortiBleed Credential Theft</title><link>https://runtimerebel.com/blog/lynx-ransomware-linked-to-massive-fortibleed-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/lynx-ransomware-linked-to-massive-fortibleed-credential-theft</guid><description>Threat actors behind Lynx and INC ransomware leverage FortiBleed campaign to harvest over 440,000 Fortinet VPN credentials via CVE-2023-48788 exploits.</description><pubDate>Thu, 02 Jul 2026 07:36:16 GMT</pubDate><category>Lynx Ransomware</category><category>INC Ransomware</category><category>CVE-2023-48788</category><category>Fortinet</category><category>Credential Theft</category><category>FortiClient EMS</category></item><item><title>CVE-2026-35616: FortiClient EMS Exploit Delivers EKZ Infostealer</title><link>https://runtimerebel.com/blog/cve-2026-35616-forticlient-ems-exploit-delivers-ekz-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35616-forticlient-ems-exploit-delivers-ekz-infostealer</guid><description>Attackers are actively exploiting CVE-2026-35616, an authentication bypass in FortiClient EMS, to deploy the EKZ infostealer. Protect your organization now.</description><pubDate>Thu, 28 May 2026 20:53:31 GMT</pubDate><category>CVE-2026-35616</category><category>FortiClient EMS</category><category>EKZ Infostealer</category><category>Authentication Bypass</category><category>Credential Stealer</category><category>Fortinet</category></item><item><title>FortiClient EMS Critical Flaw Exploited for Credential Stealing</title><link>https://runtimerebel.com/blog/forticlient-ems-critical-flaw-exploited-for-credential-stealing</link><guid isPermaLink="true">https://runtimerebel.com/blog/forticlient-ems-critical-flaw-exploited-for-credential-stealing</guid><description>Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.</description><pubDate>Thu, 28 May 2026 17:21:27 GMT</pubDate><category>FortiClient EMS</category><category>Credential Stealer</category><category>Endpoint Security</category><category>Exploitation</category><category>Malware</category></item><item><title>CVE-2023-48788: Critical FortiClient EMS RCE Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2023-48788-critical-forticlient-ems-rce-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-48788-critical-forticlient-ems-rce-under-active-exploitation</guid><description>Exploitation of CVE-2023-48788 in FortiClient EMS allows unauthenticated remote code execution. Administrators must patch to version 7.2.3 or 7.0.11 immediately.</description><pubDate>Thu, 28 May 2026 13:26:51 GMT</pubDate><category>Fortinet</category><category>CVE-2023-48788</category><category>RCE</category><category>FortiClient EMS</category><category>SQL Injection</category></item><item><title>CISA KEV Update: Fortinet FortiClient EMS CVE-2026-21643 Under Attack</title><link>https://runtimerebel.com/blog/cisa-kev-update-fortinet-forticlient-ems-cve-2026-21643-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-fortinet-forticlient-ems-cve-2026-21643-under-attack</guid><description>CISA adds six flaws to the KEV catalog, including a critical unauthenticated SQL injection in Fortinet FortiClient EMS (CVE-2026-21643). Patch immediately.</description><pubDate>Tue, 14 Apr 2026 08:40:46 GMT</pubDate><category>Fortinet</category><category>CVE-2026-21643</category><category>CISA KEV</category><category>SQL Injection</category><category>FortiClient EMS</category></item><item><title>CVE-2026-35616: Fortinet FortiClient EMS Vulnerability — KEV Alert</title><link>https://runtimerebel.com/blog/cve-2026-35616-fortinet-forticlient-ems-vulnerability-kev-alert</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35616-fortinet-forticlient-ems-vulnerability-kev-alert</guid><description>CISA adds CVE-2026-35616 affecting Fortinet FortiClient EMS to its Known Exploited Vulnerabilities catalog. Learn how to mitigate this access control flaw.</description><pubDate>Mon, 06 Apr 2026 16:23:16 GMT</pubDate><category>CVE-2026-35616</category><category>Fortinet</category><category>FortiClient EMS</category><category>KEV</category><category>Access Control</category></item><item><title>FortiClient EMS RCE via CVE-2026-35616 — Mitigation Guide</title><link>https://runtimerebel.com/blog/forticlient-ems-rce-via-cve-2026-35616-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/forticlient-ems-rce-via-cve-2026-35616-mitigation-guide</guid><description>Fortinet releases emergency patches for CVE-2026-35616, a critical SQL injection flaw in FortiClient EMS exploited to achieve unauthenticated RCE.</description><pubDate>Sun, 05 Apr 2026 20:12:25 GMT</pubDate><category>CVE-2026-35616</category><category>Fortinet</category><category>FortiClient EMS</category><category>RCE</category><category>Active Exploitation</category></item><item><title>CVE-2026-35616: Critical FortiClient EMS API Bypass Exploited</title><link>https://runtimerebel.com/blog/cve-2026-35616-critical-forticlient-ems-api-bypass-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35616-critical-forticlient-ems-api-bypass-exploited</guid><description>Fortinet releases out-of-band patches for CVE-2026-35616, a critical API access bypass in FortiClient EMS enabling unauthenticated privilege escalation.</description><pubDate>Sun, 05 Apr 2026 08:18:00 GMT</pubDate><category>CVE-2026-35616</category><category>FortiClient EMS</category><category>Fortinet</category><category>Privilege Escalation</category></item><item><title>Fortinet FortiClient EMS Critical SQLi Flaw Under Active Exploitation</title><link>https://runtimerebel.com/blog/fortinet-forticlient-ems-critical-sqli-flaw-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-forticlient-ems-critical-sqli-flaw-under-active-exploitation</guid><description>Critical SQL injection in FortiClient EMS allows unauthenticated remote code execution. Active exploitation detected, immediate patching required.</description><pubDate>Tue, 31 Mar 2026 12:31:11 GMT</pubDate><category>Fortinet</category><category>FortiClient EMS</category><category>SQL Injection</category><category>RCE</category><category>Exploitation</category></item><item><title>CVE-2023-48788: FortiClient EMS RCE via SQL Injection Exploit</title><link>https://runtimerebel.com/blog/cve-2023-48788-forticlient-ems-rce-via-sql-injection-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-48788-forticlient-ems-rce-via-sql-injection-exploit</guid><description>Exploitation of a critical RCE vulnerability (CVE-2023-48788) in Fortinet FortiClient EMS has been confirmed. Learn how to detect and mitigate this threat.</description><pubDate>Mon, 30 Mar 2026 08:40:09 GMT</pubDate><category>CVE-2023-48788</category><category>Fortinet</category><category>FortiClient EMS</category><category>RCE</category><category>SQL Injection</category></item></channel></rss>