← Vulnerability feed

Vulnerability record · CVE-2026-21643 · published 6 February 2026

CVE-2026-21643: FortiClientEMS SQL injection allows unauthenticated remote code execution

Fortinet · Forticlientems

FortiClientEMS 7.4.4 fails to neutralize special elements in SQL commands, exposing a SQL injection reachable through crafted HTTP requests. Because the flaw can be triggered without authentication and leads to unauthorized code or command execution, it is a critical pre-auth remote compromise risk for exposed management servers.

9.8 CVSS 3.1 Critical CISA KEV since 13 Apr 2026 EPSS 94% · top 0.2% CWE-89 · SQL injection
9.8CVSS 3.1 base score
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SQL injection with full code execution impact, KEV listing, near-maximum EPSS, and a public exploit make this an urgent patch-first case.

What it is

FortiClientEMS 7.4.4 fails to neutralize special elements in SQL commands, exposing a SQL injection reachable through crafted HTTP requests. Because the flaw can be triggered without authentication and leads to unauthorized code or command execution, it is a critical pre-auth remote compromise risk for exposed management servers.

Impact

An unauthenticated attacker can execute unauthorized code or commands on the FortiClientEMS host, gaining full control of the server (CVSS 9.8, C/I/A all High).

Attack surface

Reached over the network via crafted HTTP requests to the FortiClientEMS service; the CVSS vector shows no privileges and no user interaction required, so any internet- or network-exposed instance is directly attackable.

Exploitation

CISA added it to KEV on 2026-04-13 with a 2026-04-16 remediation due date, EPSS 30-day probability is 0.94085 (99.8th percentile), and a public exploit script is referenced, indicating active exploitation.

What to do

  • Apply the Fortinet vendor fix for FortiClientEMS per FG-IR-25-1142 immediately; if no fix is available for your build, follow vendor mitigations or discontinue use as CISA directs.
  • Remove FortiClientEMS management interfaces from direct internet exposure and restrict access to trusted administrative networks.
  • Treat any exposed instance as potentially compromised: rotate credentials and certificates, and review for unauthorized changes.
  • Monitor Fortinet PSIRT and CISA KEV/BOD 22-01 guidance for updated remediation instructions and deadlines.

Detection

  • Inspect HTTP request logs and WAF/IPS alerts for SQL injection patterns (UNION, stacked queries, comment sequences, tautologies) targeting FortiClientEMS endpoints.
  • Hunt for unexpected child processes, web shells, or command execution spawned by the FortiClientEMS service account.
  • Review database and application logs for anomalous queries or errors consistent with injected SQL.
  • Alert on outbound connections or new files/accounts on FortiClientEMS hosts that deviate from baseline.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-21643 to the Known Exploited Vulnerabilities catalog on 13 April 2026 as "Fortinet FortiClient EMS SQL Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 April 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21643 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-35616FortiClientEMS improper access control allows unauthenticated code executionFortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted req…KEVEPSS 9.1%analysed9.8CVE-2026-59836Fortinet forticlientems improper certificate validation vulnerabilityA improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.…EPSS 0.22%9.8CVE-2024-23106Fortinet forticlientems improper restriction of authentication attempts vulnerabilityAn improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unau…EPSS 0.96%7.2CVE-2025-59922Fortinet forticlientems sql injection vulnerabilityAn improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientE…EPSS 7.8%6.7CVE-2026-39809Fortinet forticlientems sql injection vulnerabilityA improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, …EPSS 0.20%6.1CVE-2019-16149Fortinet forticlientems cross-site scripting vulnerabilityAn Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized co…EPSS 0.28%5.5CVE-2026-39810Fortinet forticlientems vulnerabilityA use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via d…EPSS 0.15%5.3CVE-2025-22859Fortinet forticlientems relative path traversal vulnerabilityA Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remot…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2026-21643), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.