logo

Exploit released for Fortinet RCE bug used in attacks, patch now

ID: bd91a3cf-e4d2-57c3-8626-13bf0760a481

STIX ID: report--bd91a3cf-e4d2-57c3-8626-13bf0760a481

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-03-21

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Security researchers disclosed a critical SQL injection vulnerability (CVE-2023-48788) in Fortinet FortiClient EMS (affected 7.0.1–7.0.10 and 7.2.0–7.2.2) that enables unauthenticated actors to achieve remote code execution with SYSTEM privileges; a PoC exploit was published and the vendor has since acknowledged active exploitation while hundreds of EMS instances remain exposed online.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.