logo

Patch Now: Critical Fortinet RCE Bug Under Active Attack

ID: 2c65cf0f-918b-5aa4-b693-ea37068804a7

STIX ID: report--2c65cf0f-918b-5aa4-b693-ea37068804a7

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-03-26

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Executive summary: A critical SQL injection vulnerability (CVE-2023-48788, CVSS 9.3) in Fortinet FortiClient EMS can allow unauthenticated attackers to execute arbitrary code on affected systems. Researchers published a proof-of-concept demonstrating exploitation via the FcmDaemon service and use of SQL Server functionality to escalate to RCE; CISA has added the flaw to its Known Exploited Vulnerabilities catalog and Fortinet has released patches. Organizations are urged to patch immediately and examine FortiClient EMS and MS SQL logs for signs of exploitation (unexpected client connections or xp_cmdshell activity).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.