FortiClientEMS Hit by Critical SQL Injection
A critical cybersecurity flaw has left FortiClientEMS hit by a serious SQL injection vulnerability, tracked as CVE-2026-21643. The issue affects Fortinet FortiClientEMS version 7.4.4 and allows remote attackers to execute arbitrary code without authentication by sending specially crafted HTTP requests. Security experts warn that the flaw could expose critical systems to full compromise.
The vulnerability arises from improper input validation in specific HTTP request parameters, creating an entry point for SQL injection. By exploiting it, threat actors can manipulate database queries and potentially gain control of vulnerable systems. The severity of the vulnerability underscores significant risks for organizations relying on FortiClientEMS for endpoint management.
Fortinet has not issued any official mitigation guidance in the summary provided. Users are advised to follow vendor channels closely for updates. The same version of FortiClientEMS hit by this flaw remains in use across many enterprise networks.
Read the full report here:
