Critical Fortinet FortiClient EMS flaw exploited for Remote Code Execution
ID: ec847898-bc0d-593f-9e0e-a71c1447f0f9
STIX ID: report--ec847898-bc0d-593f-9e0e-a71c1447f0f9
Feed Name: Security Affairs
Threat Score
A critical Fortinet FortiClient EMS SQL injection vulnerability (CVE-2026-21643, CVSS 9.1) is being actively exploited to achieve remote code execution. Fortinet issued advisories and a patch (upgrade to FortiClientEMS 7.4.5 or above where applicable); researchers report roughly 1,000–2,000 publicly exposed instances, creating significant risk of initial network footholds, lateral movement, and malware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
