logo

CISA Warns Fortinet SQL Injection Flaw Is Being Actively Exploited

ID: ef145ec5-9183-57db-9813-dbe1afa1e4fd

STIX ID: report--ef145ec5-9183-57db-9813-dbe1afa1e4fd

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Divya

...
...

CISA has issued an urgent advisory for CVE-2026-21643, an unauthenticated SQL injection in Fortinet FortiClient EMS that can enable remote code execution; the flaw was added to CISA’s Known Exploited Vulnerabilities list, prompting immediate patching or mitigation (federal BOD 22-01 deadline April 16, 2026) and warnings that organizations should hunt for exploit attempts and follow Fortinet’s vendor guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.