logo

Critical Fortinet Forticlient EMS flaw now exploited in attacks

ID: 47208199-26ca-599d-9445-4c9e0beba3e2

STIX ID: report--47208199-26ca-599d-9445-4c9e0beba3e2

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

## Executive summary Threat actors are actively exploiting CVE-2026-21643, a critical unauthenticated SQL injection in Fortinet FortiClient EMS (7.4.4) that can lead to arbitrary code execution via crafted HTTP requests; Defused reports first exploitation and Shadowserver/Shodan enumerate thousands of exposed instances, while Fortinet recommends upgrading to 7.4.5 to patch the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.