logo

Fortinet Warns of Yet Another Critical RCE Flaw

ID: ab808f94-8711-5bee-ae81-42e7aeabc0ad

STIX ID: report--ab808f94-8711-5bee-ae81-42e7aeabc0ad

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-03-14

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Fortinet has patched a critical unauthenticated SQL-injection in FortiClient Enterprise Management Server (CVE-2023-48788) that allows remote code execution with system privileges (CVSS ~9.3–9.8); Fortinet recommends upgrading to FortiClientEMS 7.2.3 or 7.0.11 and above. Researchers at Horizon3.ai plan to release technical details, PoCs, and IOCs for this and other Fortinet flaws (several already patched, two reported unpatched), creating a narrow window for organizations to apply fixes before public exploit material appears.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.