logo

Fortinet warns of critical RCE bug in endpoint management software

ID: c5baa3f0-2b0e-514b-8048-e34219f599e0

STIX ID: report--c5baa3f0-2b0e-514b-8048-e34219f599e0

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-03-13

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Fortinet patched a critical SQL injection (CVE-2023-48788) in FortiClient EMS that allows unauthenticated remote code execution as SYSTEM on affected 7.0 and 7.2 releases; the flaw was reported by NCSC and Fortinet developers, patches are available, and Horizon3 has announced an upcoming proof-of-concept. The article also highlights additional recent Fortinet fixes (including CVE-2023-42789, CVE-2023-36554, CVE-2023-47534) and references a prior FortiOS/FortiProxy RCE (CVE-2024-21762) that was actively exploited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.