logo

Critical Fortinet FortiClient EMS flaw exploited for Remote Code Execution

ID: ec847898-bc0d-593f-9e0e-a71c1447f0f9

STIX ID: report--ec847898-bc0d-593f-9e0e-a71c1447f0f9

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical Fortinet FortiClient EMS SQL injection vulnerability (CVE-2026-21643, CVSS 9.1) is being actively exploited to achieve remote code execution. Fortinet issued advisories and a patch (upgrade to FortiClientEMS 7.4.5 or above where applicable); researchers report roughly 1,000–2,000 publicly exposed instances, creating significant risk of initial network footholds, lateral movement, and malware deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.