CVE-2026-21643 is a critical SQL injection vulnerability in Fortinet FortiClientEMS 7.4.4, enabling an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Rated 9.8 CVSS Critical, this flaw has a low attack complexity and can be exploited remotely over the network, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is currently under active exploitation in the wild, as confirmed by numerous community discussions and media reports. Despite the absence of public exploit code on common platforms, its active exploitation and high community attention underscore the immediate threat it poses to affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.4.4CPE matchmatch criteria | cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Fortinet FortiClientEMS SQL Injection (CVE-2026-21643)
Mar 24, 2026Fortinet FortiClientEMS SQL Injection (CVE-2026-21643)
Mar 24, 2026Fortinet FortiClientEMS SQL Injection (CVE-2026-21643)
Mar 24, 2026