Patch Now: Critical Fortinet RCE Bug Under Active Attack
ID: 2c65cf0f-918b-5aa4-b693-ea37068804a7
STIX ID: report--2c65cf0f-918b-5aa4-b693-ea37068804a7
Feed Name: Dark Reading
Date Published: 2024-03-26
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Executive summary: A critical SQL injection vulnerability (CVE-2023-48788, CVSS 9.3) in Fortinet FortiClient EMS can allow unauthenticated attackers to execute arbitrary code on affected systems. Researchers published a proof-of-concept demonstrating exploitation via the FcmDaemon service and use of SQL Server functionality to escalate to RCE; CISA has added the flaw to its Known Exploited Vulnerabilities catalog and Fortinet has released patches. Organizations are urged to patch immediately and examine FortiClient EMS and MS SQL logs for signs of exploitation (unexpected client connections or xp_cmdshell activity).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
