logo

CISA Warns of Fortinet SQL Injection Flaw Actively Exploited in Attacks

ID: 3f0bd708-0270-5413-88e9-6b4e83cfd4ed

STIX ID: report--3f0bd708-0270-5413-88e9-6b4e83cfd4ed

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: AnuPriya

...
...

CISA added CVE-2026-21643 — an unauthenticated SQL injection in Fortinet FortiClient Enterprise Management Server (EMS) — to its Known Exploited Vulnerabilities list after confirming active exploitation; the flaw can enable remote code execution and full system compromise, prompting an urgent federal patch/mitigation deadline and vendor updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.