logo

Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution

ID: ad5c1749-9e50-5a55-a6c8-7f99401699f9

STIX ID: report--ad5c1749-9e50-5a55-a6c8-7f99401699f9

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-02-10

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Fortinet has released updates for a critical FortiClientEMS SQL injection (CVE-2026-21643, CVSS 9.1) that could permit unauthenticated arbitrary code execution; affected FortiClientEMS versions should be upgraded to the patched releases. The advisory also calls out a separate critical Fortinet vulnerability (CVE-2026-24858, CVSS 9.4) that has been actively exploited to create persistent local admin accounts, modify VPN access, and exfiltrate firewall configurations, highlighting the urgency of applying vendor patches.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.