CVE-2026-21643criticalunder attackCWE-89

CVE-2026-21643: critical vulnerability in Fortinet FortiClientEMS

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.1epss 94%
from disclosure to weapon49 days
Published on NVDFeb 6
1st PoC+49d
CISA KEV+66d
exploitation probability
94%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2026-04-16

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

FortiClientEMS 7.4.4 has a flaw that allows attackers to inject malicious SQL code through HTTP requests without needing to log in. This can lead to unauthorized access, data theft, or system compromise.

Technical detail

SQL injection vulnerability in Fortinet FortiClientEMS 7.4.4 allows unauthenticated attackers to manipulate SQL queries via crafted HTTP requests, potentially leading to arbitrary command execution. The vulnerability results from improper input validation and sanitization of user-supplied data in SQL command construction, enabling attackers to bypass authentication and execute unauthorized code.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.