securityaffairs.com 2/9/2026, 9:55:42 PM · via preferred

Critical Fortinet FortiClientEMS flaw allows remote code execution

Critical Fortinet FortiClientEMS flaw allows remote code execution

Exploitation of Critical Fortinet FortiClient EMS Flaw Begins

Threat actors have started exploiting a critical-severity vulnerability in Fortinet FortiClient EMS, tracked as CVE-2026-21643, which is described as a pre-authentication SQL injection that can be exploited remotely via crafted HTTP requests. FortiClient EMS version 7.4.4 is affected, and a patch to 7.4.5 was released in early February, with Fortinet noting…

First seen 2026-02-09T21:55:42.941Z · Last seen 2026-03-31T11:51:41.654Z

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

FORTINET warns of a critical FortiClientEMS vulnerability that lets remote attackers run malicious code without logging in, tracked as CVE-2026-21643 with a CVSS score of 9.1. According to Fortinet, the flaw involves improper neutralization of special elements used in an SQL Command (SQL Injection), enabling an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

A successful exploit could give attackers an initial foothold in the target network, enabling lateral movement or malware deployment. The vulnerability was internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team. Affected FortiClientEMS versions are FortiClientEMS 7.4.4 (update to 7.4.5 or above is advised) and FortiClientEMS 7.2 and FortiClientEMS 8.0 are listed as not affected, with Fortinet not disclosing whether the flaw is being actively exploited in the wild. The article, dated 9 February 2026, notes that Fortinet released an urgent advisory detailing these particulars.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline