www.securityweek.com 3/31/2026, 11:51:41 AM · via preferred

Exploitation of Critical Fortinet FortiClient EMS Flaw Begins

Exploitation of Critical Fortinet FortiClient EMS Flaw Begins

Threat actors have started exploiting a critical-severity vulnerability in Fortinet FortiClient EMS, tracked as CVE-2026-21643, which is described as a pre-authentication SQL injection that can be exploited remotely via crafted HTTP requests. FortiClient EMS version 7.4.4 is affected, and a patch to 7.4.5 was released in early February, with Fortinet noting…

First seen 2026-02-09T21:55:42.941Z · Last seen 2026-03-31T11:51:41.654Z

CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

THREAT actors have started exploiting a critical-severity vulnerability in Fortinet FortiClient EMS, tracked as CVE-2026-21643, which is described as a pre-authentication SQL injection that can be exploited remotely via crafted HTTP requests. FortiClient EMS version 7.4.4 is affected, and a patch to 7.4.5 was released in early February, with Fortinet noting in its advisory that successful exploitation could lead to arbitrary code or command execution.

One month after public disclosure, Bishop Fox published technical information on the bug, warning that it was practical to exploit. Over the weekend, Defused Cyber warned that CVE-2026-21643 had been exploited for at least four days and that roughly 1,000 FortiClient EMS deployments are exposed to the internet, with The Shadowserver Foundation tracking over 2,000 internet-accessible instances as of 30 March.

Our analysis shows attackers can abuse the publicly accessible /api/v1/init_consts endpoint to trigger the SQL injection before authentication, rapidly extracting data from multi-tenant deployments, a claim supported by security researchers. According to Fortinet, the vulnerability was discovered internally.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline