logo

FortiClientEMS 7.4.4: Critical SQL Injection Flaw Exploited in the Wild

ID: a42c54c7-cfef-504c-ac5e-3d56258270b2

STIX ID: report--a42c54c7-cfef-504c-ac5e-3d56258270b2

Feed Name: Kudelski Security

Threat Score
85/100

Date Published: 2026-04-28

Date Updated: 2026-07-22

...
...

**Executive Summary:** CVE-2026-21643 is a critical unauthenticated SQL injection in Fortinet FortiClient EMS 7.4.4 that is actively exploited in the wild with public exploit material available; organizations should urgently upgrade to 7.4.5/7.4.7 or apply network segmentation, access controls, and WAF protections to limit exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.