CVE-2023-48788Active Exploitation(fortinet / forticlient_enterprise_management_server)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet forticlient_enterprise_management_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-04-15. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forticlient_enterprise_management_server

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-02-09); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
forticlient_enterprise_management_server

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-09: 1Mentions · 2026-02-18: 1Mentions · 2026-04-16: 1Mentions · 2026-06-18: 1Mentions · 2026-07-27: 1Mentions · 2026-08-18: 1Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-08-18: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-02-09: 1Technical Details · 2026-04-16: 102-0902-1804-1606-1807-2708-18
Signal classification3 categories
Active Exploitation
350.0%
General
233.3%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-091
Patch1
2026-02-181
General1
2026-04-161
Active Exploitation1
2026-06-181
Active Exploitation1
2026-07-271
General1
2026-08-181
Active Exploitation1
Full discourse6 posts
  • turingbyondu@turingbyondu
    Patch

    🤖 Nueva noticia de ciberseguridad: FORTICLIENTEMS RCE CVE-2023-48788 Claves técnicas y medidas de mitigación en este boletín ➡️ 📄

    Post summary

    A bulletin about the CVE‑2023‑48788 RCE in FortiClient EMS provides technical details and mitigation measures.

    0101088
    43 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    Medusa ransomware has escalated its attacks, compromising over 500 critical infrastructure organizations. Exploiting vulnerabilities like CVE-2024-1709 and CVE-2023-48788, it employs advanced evasion techniques, including disabling EDR systems and misusing RMM tools. Organizations must prioritize timely patching and robust cybersecurity measures to mitigate this growing threat. #MedusaRansomware #Cybersecurity #CriticalInfrastructure #Ransomware #Infosec #DataBreach https://thedailytechfeed.com/medusa-ransomware-intensifies-attacks-on-critical-infrastructure/

    Post summary

    Medusa ransomware is actively exploiting CVE-2024-1709 and CVE-2023-48788, having compromised more than 500 critical infrastructure organizations, emphasizing the need for urgent patching and enhanced defenses.

    00010116
    644 followersView on X
  • ro0TCr4k@ro0TCr4k
    General

    Fortinet FortiClient EMS CVE-2023-48788 shows endpoint management systems are prime targets. Attackers increasingly exploit the tools meant to secure enterprises. Trust in your third-party dependencies must be verified, not assumed.

    Post summary

    The post flags Fortinet FortiClient EMS CVE‑2023‑48788 as a high‑value target and urges verification of third‑party dependencies, yet it provides no technical details or evidence of exploitation.

    00000141
    483 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    INC ransomware affiliates exploited Citrix NetScaler (CVE-2023-3519) and Fortinet FortiClientEMS (CVE-2023-48788) vulnerabilities before pivoting through RDP sessions with stolen domain admin credentials. Runtime segmentation could limit such lateral movement across compromised networks. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/inc-ransomware-2026

    Post summary

    The post reports active exploitation of CVE-2023-3519 and CVE-2023-48788 by ransomware affiliates, using RDP for lateral movement, and suggests runtime segmentation could mitigate such attacks.

    0000069
    1.9K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Active Exploitation

    🔒 #CyberSecurity CISA KEV Alert: Remediate Active Exchange SSRF (CVE-2024-26234) and Fortinet RC… "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added critical…" 🔗 https://securityarsenal.com/blog/cisa-kev-alert-remediate-active-exchange-ssrf-cve-2024-26234-and-fortinet-rce-cve-2023-48788 #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    CISA released an alert for CVE-2024-26234 and Fortinet CVE-2023-48788, indicating these vulnerabilities are actively exploited in the wild and urging immediate remediation.

    0000052
    10 followersView on X
  • Proven Data@Proven_Data
    General

    INC ransomware targets Windows, Linux, and ESXi. It exploits Citrix CVE-2023-3519 and Fortinet CVE-2023-48788 to get in. Full attack lifecycle and IOCs → https://www.provendata.com/blog/inc-ransomware/ #Ransomware #CyberSecurity #IncidentResponse #ThreatIntel #InfoSec #DFIR #RansomwareAttack https://t.co/2Ur8piJCz3

    Post summary

    The tweet reports that the INC ransomware uses CVE‑2023‑3519 and CVE‑2023‑48788 to target multiple platforms, and directs readers to a blog for the full attack lifecycle and IOCs.

    0000096
    913 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetforticlient_enterprise_management_server---

Explore more