logo

CVE-2026-21643: Critical FortiClient EMS Vulnerability Enables Unauthenticated Remote Code Execution

ID: 52a87840-2e6a-5c30-b58c-46da483fc5d2

STIX ID: report--52a87840-2e6a-5c30-b58c-46da483fc5d2

Feed Name: SOC Prime Blog

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Fortinet released an advisory for CVE-2026-21643: a critical (CVSS 9.8) pre-auth SQL injection in FortiClient EMS 7.4.4 that can be exploited via crafted HTTP requests to potentially execute unauthorized commands or escalate to full system compromise; Fortinet fixed the issue in 7.4.5 and recommends patching, restricting access to the EMS web interface, and increasing monitoring while noting no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.