Your endpoint manager just delivered malware to every device it manages.

Your endpoint manager just delivered malware to every device it manages. That is not a hypothetical. It happened this week. CVE-2026-35616 is a pre-authentication API bypass in FortiClient Endpoint Management Server (EMS). CVSS 9.1. Actively exploited. Here is what the attack looks like: the attacker authenticates to your EMS without credentials, takes control of the…

Read More