logo

Endpoint Exposed: Critical FortiClient EMS Flaw (CVSS 9.1) Allows Unauthenticated RCE

ID: a27fb669-bbe2-5bca-9a69-af6a4ff264ef

STIX ID: report--a27fb669-bbe2-5bca-9a69-af6a4ff264ef

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-09

Date Updated: 2026-04-23

Author: Ddos

...
...

### Critical SQL Injection in FortiClient EMS (CVE-2026-21643) Fortinet issued a high-priority advisory for an unauthenticated SQL Injection in FortiClient Enterprise Management Server (FortiClientEMS 7.4.4) that can lead to arbitrary code execution (CVSS 9.1); administrators should upgrade to 7.4.5 or above immediately (branches 8.0 and 7.2 are not affected).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.