Critical Fortinet FortiClient EMS bug under active attack (CVE-2026-21643)
ID: ff6765c5-9974-5172-978f-67830bd61be2
STIX ID: report--ff6765c5-9974-5172-978f-67830bd61be2
Feed Name: Help Net Security
### Executive Summary A critical SQL injection (CVE-2026-21643) in Fortinet FortiClient EMS v7.4.4 (multi-tenant deployments) allows unauthenticated remote attackers to inject SQL via an HTTP header used to select tenant context, enabling access to admin credentials, inventory, policies, and certificates. Defused Cyber reports exploitation in the wild days ago, Shodan lists ~1,000 exposed EMS instances, and Fortinet has released a fix in v7.4.5; organizations using 7.4.4 with multi-tenant mode should upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
