Critical Fortinet Forticlient EMS flaw now exploited in attacks
7 Articles
7 Articles
Fortinet hit by another exploited cybersecurity flaw
Yet another critical flaw in a Fortinet product has come to light as attackers continue to target the company, this time by actively exploiting a critical SQL injection vulnerability in the cybersecurity company’s management server. The vulnerability, (CVE-2026-21643), allows unauthenticated threat actors to execute arbitrary code on unpatched systems via specifically-crafted HTTP requests. These low-complexity attacks target the FortiClient End…
In February, Fortinet considered a critical vulnerability in FortiClient EMS with a security patch. It is now under attack.
Critical Fortinet Forticlient EMS Vulnerability Exploited in Attacks
A critical SQL injection vulnerability in Fortinet’s FortiClient Endpoint Management Server (EMS), tracked as CVE-2026-21643, is actively being exploited in the wild. Threat actors have been leveraging this flaw in attacks starting four days ago, despite it not yet appearing on the CISA Known Exploited Vulnerabilities catalog. The security flaw affects FortiClient EMS version 7.4.4, […] The post Critical Fortinet Forticlient EMS Vulnerability Ex…
FortiClient EMS has been facing attacks on a critical flaw that has been corrected for weeks. These include still vulnerable servers and management interfaces that are still accessible from the Internet.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium





