Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution
ID: ad5c1749-9e50-5a55-a6c8-7f99401699f9
STIX ID: report--ad5c1749-9e50-5a55-a6c8-7f99401699f9
Feed Name: The Hacker News
**Fortinet has released updates for a critical FortiClientEMS SQL injection (CVE-2026-21643, CVSS 9.1) that could permit unauthenticated arbitrary code execution; affected FortiClientEMS versions should be upgraded to the patched releases. The advisory also calls out a separate critical Fortinet vulnerability (CVE-2026-24858, CVSS 9.4) that has been actively exploited to create persistent local admin accounts, modify VPN access, and exfiltrate firewall configurations, highlighting the urgency of applying vendor patches.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
