CVE-2026-21643: critical vulnerability in Fortinet FortiClientEMS
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
FortiClientEMS 7.4.4 has a flaw that allows attackers to inject malicious SQL code through HTTP requests without needing to log in. This can lead to unauthorized access, data theft, or system compromise.
SQL injection vulnerability in Fortinet FortiClientEMS 7.4.4 allows unauthenticated attackers to manipulate SQL queries via crafted HTTP requests, potentially leading to arbitrary command execution. The vulnerability results from improper input validation and sanitization of user-supplied data in SQL command construction, enabling attackers to bypass authentication and execute unauthorized code.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.