cbcvebase.
CVE-2026-21643
published 2026-02-06

CVE-2026-21643: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an…

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2026-04-16
Exploited in the wild
EPSS
94.08%
99.8th percentile
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Affected

3 ranges
VendorProductVersion rangeFixed in
fortinetforticlientems
fortinetforticlientems
fortinetfortinet

Detection & IOCsextracted from sources · hover to see the quote

otherSite header (HTTP) used to smuggle SQL statements
  • Monitor HTTP requests to FortiClient EMS web interface (GUI) for SQL injection payloads embedded in the 'Site' HTTP header.
  • Flag unauthenticated HTTP requests containing SQL syntax in non-standard headers targeting FortiClient EMS endpoints.
  • Identify internet-exposed FortiClient EMS instances (version 7.4.4) as high-priority targets; Shadowserver tracks over 2,000 exposed instances with 1,400+ IPs in the US and Europe.
  • ·Vulnerability affects only FortiClient EMS version 7.4.4; patched in version 7.4.5 or later.
  • ·Exploitation requires no authentication and is low-complexity, making any internet-exposed instance an immediate risk.
  • ·As of reporting, CVE-2026-21643 was not yet listed on CISA KEV despite confirmed in-the-wild exploitation observed 4 days prior.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.8HIGH
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.