SecPod

Learn Search

Search across all Learn content

← Back to Security Research
FortiClient EMS Under Fire: Critical CVE-2026-21643 Exploited in Real-World Attacks

FortiClient EMS Under Fire: Critical CVE-2026-21643 Exploited in Real-World Attacks

A critical SQL injection vulnerability, CVE-2026-21643, has been identified in FortiClient Endpoint Management Server (EMS), a centralized management platform for FortiClient endpoint agents across multiple environments.

Mar 30, 2026By Rakshitha3 min read

A critical SQL injection vulnerability, CVE-2026-21643, has been identified in FortiClient Endpoint Management Server (EMS), a centralized management platform for FortiClient endpoint agents across multiple environments.

The vulnerability is currently under active exploitation in the wild, even though it is not yet listed in major exploited vulnerability catalogs. Early attack activity indicates that threat actors are already targeting exposed systems.

This issue poses a serious risk to organizations that have their FortiClient EMS administrative interface accessible over the internet, as it allows remote compromise without authentication.

Vulnerability Details:

  • CVE-ID: CVE-2026-21643
  • CVSS Score: 9.8 (Critical) 
  • EPSS Score: 0.05%
  • Vulnerability: SQL Injection vulnerability 
  • Affected Product: Fortinet FortiClientEMS

Root Cause

CVE-2026-21643 is caused by improper neutralization of special elements in SQL commands, resulting in a SQL injection vulnerability.

The flaw was introduced in FortiClient EMS during changes to the middleware and database connection layer to support enhanced multi-tenant functionality.

Specifically, an HTTP header used to identify tenant context is passed directly into a backend SQL query without proper sanitization, and this occurs before authentication is enforced.

Impact

This vulnerability allows remote, unauthenticated attackers to:

  • Execute arbitrary SQL queries on the backend PostgreSQL database
  • Access highly sensitive information, including:
    • Administrative credentials
    • Endpoint inventory data
    • Security policies
    • Certificates for managed endpoints
  • Potentially execute unauthorized commands or code on the server

Due to the absence of authentication requirements and the sensitivity of exposed data, the impact is considered critical.

Infection Method / Exploitation Technique

The exploitation process is simple and highly effective:

VersionAffectedSolution
FortiClientEMS 8.0Not affectedNot Applicable
FortiClientEMS 7.47.4.4Upgrade to 7.4.5 or above
FortiClientEMS 7.2Not affectedNot Applicable
  1. The attacker connects to the FortiClient EMS web interface over HTTPS
  2. A specially crafted HTTP request is sent to the server
  3. The request contains a malicious tenant-identification HTTP header
  4. This header is directly incorporated into a SQL query without validation
  5. The injected SQL is executed by the database

Mitigation & Recommendations

To reduce the risk of exploitation of CVE-2026-21643 in Fortinet FortiClient EMS, organizations should take immediate action:

  • Update FortiClient EMS from version 7.4.4 to 7.4.5 or later, where the vulnerability has been fixed.
  • Limit exposure of the EMS administrative interface by:
    • Removing public internet access
    • Allowing access only via VPN or trusted internal networks

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited
Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

CVE Research

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.

Sep 28, 2026

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026