Endpoint Exposed: Critical FortiClient EMS Flaw (CVSS 9.1) Allows Unauthenticated RCE
ID: a27fb669-bbe2-5bca-9a69-af6a4ff264ef
STIX ID: report--a27fb669-bbe2-5bca-9a69-af6a4ff264ef
Feed Name: securityonline.info
Threat Score
### Critical SQL Injection in FortiClient EMS (CVE-2026-21643) Fortinet issued a high-priority advisory for an unauthenticated SQL Injection in FortiClient Enterprise Management Server (FortiClientEMS 7.4.4) that can lead to arbitrary code execution (CVSS 9.1); administrators should upgrade to 7.4.5 or above immediately (branches 8.0 and 7.2 are not affected).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
