FortiClientEMS Vulnerabilities Under Active Exploitation, Expose Systems to RCE
ID: 04032dd7-08b3-5324-9a95-3f012ccc3cdc
STIX ID: report--04032dd7-08b3-5324-9a95-3f012ccc3cdc
Feed Name: The Cyber Express
Threat Score
**Executive summary:** Fortinet FortiClientEMS contains two critical, actively exploited vulnerabilities (CVE-2026-21643: unauthenticated SQL injection in administrative interface; CVE-2026-35616: improper access control allowing API auth bypass and unauthenticated RCE) affecting specific 7.4.x releases; vendors and government agencies (CISA, CSA) have issued advisories and recommended immediate application of hotfixes and upgrades to remediate the issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
