Fortinet has issued an urgent advisory regarding a critical vulnerability in FortiClientEMS, identified as CVE-2026-21643, with a CVSS score of 9.1. This SQL injection flaw allows unauthenticated attackers to execute unauthorized code via crafted HTTP requests, posing a significant risk to network security, with further coverage provided by Security Affairs.The vulnerability, an improper neutralization of special elements used in an SQL command, enables remote attackers to run malicious code without prior authentication. A successful exploit could grant attackers an initial foothold within a target network, facilitating lateral movement or the deployment of malware. The issue was internally discovered and reported by Gwendal Guégniaud of Fortinet's Product Security team. Affected versions include FortiClientEMS 7.4.4, with a recommended upgrade to version 7.4.5 or later. FortiClientEMS 8.0 and 7.2 are not affected.Source: Security Affairs
Network Security, Vulnerability Management, Patch/Configuration Management
Fortinet FortiClientEMS vulnerability allows remote code execution
(Adobe Stock)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
