CVE-2026-21643: Critical FortiClient EMS Vulnerability Enables Unauthenticated Remote Code Execution
ID: 52a87840-2e6a-5c30-b58c-46da483fc5d2
STIX ID: report--52a87840-2e6a-5c30-b58c-46da483fc5d2
Feed Name: SOC Prime Blog
Threat Score
Fortinet released an advisory for CVE-2026-21643: a critical (CVSS 9.8) pre-auth SQL injection in FortiClient EMS 7.4.4 that can be exploited via crafted HTTP requests to potentially execute unauthorized commands or escalate to full system compromise; Fortinet fixed the issue in 7.4.5 and recommends patching, restricting access to the EMS web interface, and increasing monitoring while noting no evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
