Skip to main content

Share story

Security

Critical Fortinet FortiClient EMS bug under active attack (CVE-2026-21643)

Critical Fortinet FortiClient EMS bug under active attack (CVE-2026-21643) Image: Primary
A critical SQL injection vulnerability in Fortinet FortiClient Endpoint Management Server is under active exploitation, according to threat intelligence firm Defused. The flaw, identified as CVE-2026-21643, was discovered internally by Fortinet Product Security team member Gwendal Guégniaud. It stems from improper neutralization of special elements in SQL commands and affects only deployments running FortiClientEMS version 7.4.4. Remote unauthenticated attackers can exploit it by sending specially crafted HTTP requests to internet-exposed administrative interfaces, potentially allowing unauthorized code or command execution. Defused stated that exploitation was first observed four days ago through its honeypot data, even though the vulnerability remains unmarked on CISA and other known exploited vulnerabilities lists. Fortinet has not yet confirmed the exploitation reports. The company fixed the issue in version 7.4.5, released in December 2026. Branches 7.2 and 8.0 are not affected. Bishop Fox researchers published a technical analysis of the vulnerability in early March 2026. They noted that a refactor of the middleware and database connection layer for multi-tenant support in version 7.4.4 introduced the flaw by passing a tenant-identifying HTTP header directly into a PostgreSQL database query without sanitization and before any login check. A single crafted request can execute arbitrary SQL, granting access to administrative credentials, endpoint inventory data, security policies, and certificates for managed endpoints. Bishop Fox advised organizations running FortiClient EMS 7.4.4 with multi-tenant mode enabled to upgrade immediately to version 7.4.5. Single-site deployments are not affected. Defused reported that Shodan shows close to 1,000 publicly exposed FortiClient EMS instances, though the number running the vulnerable version in multi-tenant mode is unknown.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Help Net Security and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital AI
Capital AI

Enveda raises $311 million to advance AI-assisted drug candidates

Enveda has raised $311 million in Series E financing at a $2 billion valuation as it moves drug candidates found through its AI-assisted search of natural compounds into human testing. Catalio Capital Management led the round, wit...

Capital AI
Capital AI

Lightspeed targets $250 million for AI-focused India fund

Lightspeed is seeking $250 million for a new early-stage India fund focused on AI companies, with commitments for 80% of that target already secured, TechCrunch reported from a letter to investors. The proposed fund is half the si...

Science
Science

Infleqtion claims 30 entangled logical qubits on Sqale system

Infleqtion says it created 30 entangled logical qubits on its Sqale quantum computing system, a company-reported step toward operations across error-protected quantum bits. A logical qubit encodes information across multiple physi...

Capital AI
Capital AI

NUS Enterprise launches patent-matching platform and Munich outpost

NUS Enterprise says it has launched Nova, an AI platform developed with Zima Labs to help its staff find commercial partners for university research. It has also established an outpost in Munich through a partnership with Unterneh...

AI Policy
AI Policy

White House asks AI labs to delay model access for UK testers

The White House has asked OpenAI and Anthropic to keep new AI models from the UK's AI Security Institute until the US government tests them, Politico reported. A British official confirmed the reported request to Bloomberg. Politi...

AI Products
AI Products

Microsoft unveils Copilot app with coding and autonomous agents

Microsoft unveiled a redesigned Copilot app that brings chat, coding and autonomous agents into one interface for work. Its Home tab combines chat and task assistance, while Code is designed to create internal apps in a sandbox ho...