CVE-2026-21643
published 2026-02-06CVE-2026-21643: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2026-04-16
Exploited in the wild
EPSS
94.08%
99.8th percentile
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlientems | — | — |
| fortinet | forticlientems | — | — |
| fortinet | fortinet | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP requests to FortiClient EMS web interface (GUI) for SQL injection payloads embedded in the 'Site' HTTP header. ↗
- →Flag unauthenticated HTTP requests containing SQL syntax in non-standard headers targeting FortiClient EMS endpoints. ↗
- →Identify internet-exposed FortiClient EMS instances (version 7.4.4) as high-priority targets; Shadowserver tracks over 2,000 exposed instances with 1,400+ IPs in the US and Europe. ↗
- ·Vulnerability affects only FortiClient EMS version 7.4.4; patched in version 7.4.5 or later. ↗
- ·Exploitation requires no authentication and is low-complexity, making any internet-exposed instance an immediate risk. ↗
- ·As of reporting, CVE-2026-21643 was not yet listed on CISA KEV despite confirmed in-the-wild exploitation observed 4 days prior. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.8HIGH
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Fortinet FortiClientEMS 7.4.4 sql injection (FG-IR-25-1142 / Nessus ID 304507)
vuldb·2026-04-13·CVSS 9.8
CVE-2026-21643 [CRITICAL] Fortinet FortiClientEMS 7.4.4 sql injection (FG-IR-25-1142 / Nessus ID 304507)
A vulnerability was found in Fortinet FortiClientEMS 7.4.4. It has been classified as critical. Impacted is an unknown function. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-21643. The attack is possible to be carried out remotely. Moreover, an exploit is present.
GHSA
GHSA-r6vr-hwpr-qqch: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7
ghsa_unreviewed·2026-02-06
CVE-2026-21643 [CRITICAL] CWE-89 GHSA-r6vr-hwpr-qqch: An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
VulnCheck
Fortinet forticlientems Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
vulncheck·2026·CVSS 9.8
CVE-2026-21643 [CRITICAL] Fortinet forticlientems Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Fortinet forticlientems Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Affected: Fortinet forticlientems
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.linkedin.com/posts/defused_fortinet-forticlient-ems-cve-2026-21643-activity-7443678408401756160-nZlK; https://x.com/defusedcyber/status/2037912573274636781; https://www.secpod.com/blog/forticlient-ems-under
CISA
Fortinet FortiClient EMS SQL Injection Vulnerability
cisa·2026-04-13·CVSS 9.8
CVE-2026-21643 [CRITICAL] CWE-89 Fortinet FortiClient EMS SQL Injection Vulnerability
Vulnerability: Fortinet FortiClient EMS SQL Injection Vulnerability
Affected: Fortinet FortiClient EMS
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-1142 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21643
Remediation Due Date: 2026-04-16
Fortinet
SQLi in administrative interface
vendor_fortinet·2026-02-06·CVSS 9.8
CVE-2026-21643 [CRITICAL] CWE-89 SQLi in administrative interface
FG-IR-25-1142: SQLi in administrative interface
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVEs: CVE-2026-21643
CWEs: CWE-89
CVSS: 9.8 (critical)
Affected products: FortiClientEMS, FortiClientems, Fortinet
Suricata
ET WEB_SPECIFIC_APPS Fortigate Forticlient EMS HTTP Site Header SQL injection attempt (CVE-2026-21643)
suricata·2026-03-26·CVSS 9.8
CVE-2026-21643 [CRITICAL] ET WEB_SPECIFIC_APPS Fortigate Forticlient EMS HTTP Site Header SQL injection attempt (CVE-2026-21643)
ET WEB_SPECIFIC_APPS Fortigate Forticlient EMS HTTP Site Header SQL injection attempt (CVE-2026-21643)
Rule: alert http1 any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Fortigate Forticlient EMS HTTP Site Header SQL injection attempt (CVE-2026-21643)"; flow:established,to_server; http.uri; content:"/api/v1/"; startswith; fast_pattern; pcre:"/^(?:init_consts|auth\x2fsignin)$/R"; http.header; content:"Site|3a 20|"; pcre:"/^[^<]*?(?:'|%27|-{2}|%2d%2d)?(?:(?:S(?:HOW.+(?:C(?:UR(?:DAT|TIM)E|HARACTER.+SET)|(?:VARI|T)ABLES)|ELECT.+(?:FROM|USER|SLEEP|CONCAT|CASE))|U(?:NION.+SELEC|PDATE.+SE)T|DELETE.+FROM|INSERT.+INTO)|S(?:HOW.+(?:C(?:HARACTER.+SET|UR(DATE|TIME))|(?:VARI|T)ABLES)|ELECT.+(?:FROM|USER))|U(?:NION.+SELEC|PDATE.+SE)T|(?:NULL(?:\x2c|%2[cC])){2,}|(?:\x2f|%2[fF])(?:\x2a|%2[aA]).+(?:\x2
Suricata
ET HUNTING Fortigate Forticlient EMS Multi-Tennant Fingerprinting Attempt
suricata·2026-03-26
CVE-2026-21643 ET HUNTING Fortigate Forticlient EMS Multi-Tennant Fingerprinting Attempt
ET HUNTING Fortigate Forticlient EMS Multi-Tennant Fingerprinting Attempt
Rule: alert http any any -> $HOME_NET any (msg:"ET HUNTING Fortigate Forticlient EMS Multi-Tennant Fingerprinting Attempt"; flow:established,to_server; http.method; content:"GET"; http.uri; bsize:19; content:"/api/v1/init_consts"; fast_pattern; reference:url,bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4; classtype:network-scan; sid:2068436; rev:1; metadata:affected_product FortiClient_EMS, attack_target Server, tls_state TLSDecrypt, created_at 2026_03_26, deployment Perimeter, deployment Internal, deployment SSLDecrypt, performance_impact Low, confidence High, signature_severity Minor, updated_at 2026_03_26; target:dest_ip;)
Nuclei
Fortinet FortiClientEMS 7.4.4 - SQL Injection
nuclei·CVSS 9.8
CVE-2026-21643 [CRITICAL] Fortinet FortiClientEMS 7.4.4 - SQL Injection
Fortinet FortiClientEMS 7.4.4 - SQL Injection
Fortinet FortiClientEMS version 7.4.4 and earlier contains an unauthenticated SQL injection vulnerability in the /api/v1/init_consts endpoint. The 'Site' HTTP header value is passed directly into the PostgreSQL search_path without sanitization, allowing remote unauthenticated attackers to inject arbitrary SQL commands. This can lead to information disclosure, database manipulation, or OS command execution when chained with PostgreSQL functions.
Template:
id: CVE-2026-21643
info:
name: Fortinet FortiClientEMS 7.4.4 - SQL Injection
author: ritikchaddha
severity: critical
description: |
Fortinet FortiClientEMS version 7.4.4 and earlier contains an unauthenticated SQL injection vulnerability in the /api/v1/init_consts endpoint. The 'Site' HTTP
Bleepingcomputer
Critical Fortinet FortiSandbox flaws now exploited in attacks
blogs_bleepingcomputer·2026-06-16·CVSS 6.5
CVE-2026-39813 [MEDIUM] Critical Fortinet FortiSandbox flaws now exploited in attacks
## Critical Fortinet FortiSandbox flaws now exploited in attacks
## Sergiu Gatlan
Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused.
Fortinet released security updates for these three critical-severity security flaws (tracked as CVE-2026-39813 , CVE-2026-39808 , and CVE-2026-25089 ) on April 14.
These flaws allow unauthenticated threat actors to escalate privileges and execute unauthorized code remotely through low-complexity command injection attacks that require no user interaction. To resolve these issues and block incoming attacks, admins must upgrade affected deployments to the latest released versions.
"We are observing exploitation of multiple Fortinet FortiS
Bleepingcomputer
Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
blogs_bleepingcomputer·2026-05-12·CVSS 9.8
CVE-2026-44277 [CRITICAL] Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
## Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
## Sergiu Gatlan
Fortinet has released security updates to address two critical vulnerabilities in FortiSandbox and FortiAuthenticator that could enable attackers to run commands or arbitrary code on unpatched systems.
The first one, tracked as CVE-2026-44277, impacts the company's FortiAuthenticator Identity and Access Management (IAM) solution and was patched in FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3.
"An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests," Fortinet said in a Tuesday advisory .
The company added that FortiAuthenticator Cloud (formerly known as FortiTrust Iden
Hackernews
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
blogs_hackernews·2026-04-14·CVSS 7.8
[HIGH] CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added half a dozen security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation.
The list of vulnerabilities is as follows -
CVE-2026-21643 (CVSS score: 9.1) - An SQL injection vulnerability in Fortinet FortiClient EMS that could allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVE-2020-9715 (CVSS score: 7.8) - A use-after-free vulnerability in Adobe Acrobat Re
Bleepingcomputer
CISA orders feds to patch exploited Fortinet EMS flaw by Friday
blogs_bleepingcomputer·2026-04-06·CVSS 9.8
CVE-2026-35616 [CRITICAL] CISA orders feds to patch exploited Fortinet EMS flaw by Friday
## CISA orders feds to patch exploited Fortinet EMS flaw by Friday
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to secure FortiClient Enterprise Management Server (EMS) instances against an actively exploited vulnerability by Friday.
Tracked as CVE-2026-35616, this security flaw was discovered by cybersecurity firm Defused, which described it as a pre-authentication API access bypass that can allow attackers to bypass authentication and authorization controls entirely.
Fortinet released emergency hotfixes over the weekend to address the vulnerability and said the security issue stems from an improper access control weakness that unauthenticated attackers can exploit to execute code or commands via specially crafted requests.
Tenable
CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild
blogs_tenable·2026-04-06·CVSS 9.8
[CRITICAL] CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Hackernews
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
blogs_hackernews·2026-04-06
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there.
One weak spot now spreads wider than before. What starts small can reach a lot of systems fast. New bugs, faster use, less time to react.
That’s this week. Read through it.
## ⚡ Threat of the Week
Axios npm Package Compromised by N. Korean Hackers —Threat actors with ties to North Korea seized control of the npm account belonging to the lead m
Hackernews
Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
blogs_hackernews·2026-04-05·CVSS 9.8
CVE-2026-35616 [CRITICAL] Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
Fortinet has released out-of-band patches for a critical security flaw impacting FortiClient EMS that it said has been exploited in the wild.
The vulnerability, tracked as CVE-2026-35616 (CVSS score: 9.1), has been described as a pre-authentication API access bypass leading to privilege escalation.
"An improper access control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests," Fortinet said in a Saturday advisory.
The issue affects FortiClient EMS versions 7.4.5
Bleepingcomputer
New FortiClient EMS flaw exploited in attacks, emergency patch released
blogs_bleepingcomputer·2026-04-05·CVSS 9.8
CVE-2026-35616 [CRITICAL] New FortiClient EMS flaw exploited in attacks, emergency patch released
## New FortiClient EMS flaw exploited in attacks, emergency patch released
## Lawrence Abrams
Fortinet has released an emergency weekend security update for a new critical FortiClient Enterprise Management Server (EMS) vulnerability that is actively exploited in attacks.
Tracked as CVE-2026-35616, the flaw is an improper access control vulnerability that allows unauthenticated attackers to execute code or commands via specially crafted requests.
The issue was patched Saturday, with Fortinet confirming it has been exploited in the wild.
"Fortinet has observed this to be exploited in the wild and urges vulnerable customers to install the hotfix for FortiClient EMS 7.4.5 and 7.4.6," warns Fortinet .
Fortinet says the vulnerability impacts FortiClient EMS versions 7.4.5 and 7.4.6 and can
Bleepingcomputer
Critical Fortinet Forticlient EMS flaw now exploited in attacks
blogs_bleepingcomputer·2026-03-30·CVSS 9.8
CVE-2026-21643 [CRITICAL] Critical Fortinet Forticlient EMS flaw now exploited in attacks
## Critical Fortinet Forticlient EMS flaw now exploited in attacks
## Sergiu Gatlan
Attackers are now actively exploiting a critical vulnerability in Fortinet's FortiClient EMS platform, according to threat intelligence company Defused.
Tracked as CVE-2026-21643 , this SQL injection vulnerability allows unauthenticated threat actors to execute arbitrary code or commands on unpatched systems through low-complexity attacks targeting the FortiClientEMS GUI (web interface) via maliciously crafted HTTP requests.
"Fortinet Forticlient EMS CVE-2026-21643 - currently marked as not exploited on CISA and other Known Exploited Vulnerabilities (KEV) lists - has seen first exploitation already 4 days ago according to our data," Defused warned over the weekend.
"Attackers can smuggle SQL statements
Hackernews
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
blogs_hackernews·2026-03-30·CVSS 9.3
[CRITICAL] ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention.
There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to.
All of it below. Let's go.
## ⚡ Threat of the Week
Citrix Flaw Comes Under Active Exploitation — A cr
Hackernews
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
blogs_hackernews·2026-03-23
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories.
This edition covers a mix of issues: supply chain attacks hitting CI/CD setups, long-abused IoT devices being shut down, and exploits moving quickly from disclosure to real attacks. There are also new malware tricks showing attackers are becoming more patient and creative.
It’s a mix of old problems that never go away and new methods that are harder to detect. Th
Wiz
CVE-2026-21643 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-21643 [CRITICAL] CVE-2026-21643 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21643 :
FortiClient EMS vulnerability analysis and mitigation
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Source : NVD
## 9.8
Score
Published February 6, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
FortiClient EMS
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient_endpoint_management_server
Sources
Windows Severity CRITICAL Has Fix Added at: Feb 11
Wiz
CVE-2026-35616 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-35616 [CRITICAL] CVE-2026-35616 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-35616 :
FortiClient EMS vulnerability analysis and mitigation
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Source : NVD
## 9.8
Score
Published April 4, 2026
Severity CRITICAL
CNA Score 9.8
High-profile Vulnerability Yes
Affected Technologies
FortiClient EMS
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 90.6
Exploitation Probability (EPSS) 6
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient_enterprise_management_server
Sources
Windows Severity CRITICAL Has Fix Added at: Apr 05, 2026
## Get a CVE risk assessmen
2026-02-06
Published
2026-04-13
Added to CISA KEV
Exploited in the wild