⚠ Actively exploited
Added to CISA KEV on 2026-04-13. Federal agencies required to patch by 2026-04-16. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2026-21643

CWE-89SQL Injection12 documents11 sources
Severity
9.8CRITICAL
EPSS
13.7%
top 5.74%
CISA KEV
KEV
Added 2026-04-13
Due 2026-04-16
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 6
KEV addedApr 13
KEV dueApr 16
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/forticlientems7.4.07.4.5
CVEListV5fortinet/forticlientems7.4.4

🔴Vulnerability Details

4
VulDB
Fortinet FortiClientEMS 7.4.4 sql injection (FG-IR-25-1142 / Nessus ID 304507)2026-04-13
GHSA
GHSA-r6vr-hwpr-qqch: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 72026-02-06
CVEList
CVE-2026-21643: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 72026-02-06
VulnCheck
Fortinet forticlientems Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2026

💥Exploits & PoCs

1
Nuclei
Fortinet FortiClientEMS 7.4.4 - SQL Injection

🔍Detection Rules

2
Suricata
ET WEB_SPECIFIC_APPS Fortigate Forticlient EMS HTTP Site Header SQL injection attempt (CVE-2026-21643)2026-03-26
Suricata
ET HUNTING Fortigate Forticlient EMS Multi-Tennant Fingerprinting Attempt2026-03-26

📋Vendor Advisories

2
CISA
Fortinet SQL Injection Vulnerability2026-04-13
Fortinet
SQLi in administrative interface2026-02-06

🕵️Threat Intelligence

2
Bleepingcomputer
Critical Fortinet Forticlient EMS flaw now exploited in attacks2026-03-30
Wiz
CVE-2026-21643 Impact, Exploitability, and Mitigation Steps | Wiz