peter bassill · operator
$ cve CVE-2026-21643 JSON

CVE-2026-21643 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 93.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-04-16.

Description

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS93.72% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVyes — remediate by 2026-04-16
Public exploitnone known
Published2026-02-06
Last modified2026-06-17

CISA KEV

NameFortinet FortiClient EMS SQL Injection Vulnerability
Added2026-04-13
Due2026-04-16
Vendor / productFortinet / FortiClient EMS
Ransomware usenone reported

Affected (1)

VendorProduct
fortinetforticlientems

References

→ the Explorer  ·  watch your stack  ·  NVD