Critical Fortinet FortiClientEMS flaw allows remote code execution
ID: 14f33a46-3227-55cc-bc94-8128abcf01ea
STIX ID: report--14f33a46-3227-55cc-bc94-8128abcf01ea
Feed Name: Security Affairs
Threat Score
Fortinet published an urgent advisory for CVE-2026-21643, a critical SQL injection in FortiClientEMS (CVSS 9.1) that can enable unauthenticated remote code execution via specially crafted HTTP requests; FortiClientEMS 7.4.4 is affected and users are advised to upgrade to 7.4.5 or later. The flaw was discovered internally by Fortinet's Product Security team, and Fortinet has not reported active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
