CVE-2026-21643 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 93.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2026-04-16.
Description
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 93.72% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | yes — remediate by 2026-04-16 |
| Public exploit | none known |
| Published | 2026-02-06 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet FortiClient EMS SQL Injection Vulnerability |
|---|---|
| Added | 2026-04-13 |
| Due | 2026-04-16 |
| Vendor / product | Fortinet / FortiClient EMS |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| fortinet | forticlientems |
References
→ the Explorer · watch your stack · NVD