CVE-2026-21643Active Exploitation(fortinet / forticlientems)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 30 mentions and remains active

Immediate actions

  • Patch fortinet forticlientems systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-89

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forticlientems

Threat summary

  • Active exploitation appears in 124 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 233 mentions across 51 observed days

What's happening

  • Active exploitation reported across 124 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 28 signals
  • Patch or workaround mentioned in 99 signals
  • Technical details provided in 184 signals
  • Disclosure: 42 classified signals
  • Peaked 32d ago at 30 mentions (2026-03-30); latest day: 2
  • 233 total mentions across 51 days

Affected systems

Vendors
Products
forticlientems

1 version affected across 1 product

Deep dive

Activity timeline233 mentions / 51d
08152330Mentions · 2026-02-06: 8Mentions · 2026-02-09: 4Mentions · 2026-02-10: 24Mentions · 2026-02-11: 10Mentions · 2026-02-14: 1Mentions · 2026-02-16: 1Mentions · 2026-02-19: 1Mentions · 2026-02-23: 1Mentions · 2026-02-25: 1Mentions · 2026-03-10: 2Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-17: 3Mentions · 2026-03-18: 3Mentions · 2026-03-19: 1Mentions · 2026-03-26: 1Mentions · 2026-03-28: 2Mentions · 2026-03-30: 30Mentions · 2026-03-31: 20Mentions · 2026-04-01: 15Mentions · 2026-04-03: 4Mentions · 2026-04-04: 5Mentions · 2026-04-05: 9Mentions · 2026-04-06: 15Mentions · 2026-04-07: 10Mentions · 2026-04-09: 2Mentions · 2026-04-10: 2Mentions · 2026-04-12: 1Mentions · 2026-04-13: 5Mentions · 2026-04-14: 5Mentions · 2026-04-15: 3Mentions · 2026-04-16: 7Mentions · 2026-04-17: 4Mentions · 2026-04-18: 2Mentions · 2026-04-19: 3Mentions · 2026-04-20: 2Mentions · 2026-04-21: 2Mentions · 2026-04-23: 1Mentions · 2026-04-24: 3Mentions · 2026-04-27: 3Mentions · 2026-05-01: 1Mentions · 2026-05-04: 1Mentions · 2026-05-08: 2Mentions · 2026-05-12: 1Mentions · 2026-05-19: 1Mentions · 2026-05-21: 2Mentions · 2026-06-16: 2Mentions · 2026-06-17: 1Mentions · 2026-08-11: 1Mentions · 2026-10-10: 2PoC Mentioned / Linked · 2026-02-06: 1PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-02-11: 1PoC Mentioned / Linked · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-18: 1PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-03-30: 3PoC Mentioned / Linked · 2026-03-31: 3PoC Mentioned / Linked · 2026-04-01: 5PoC Mentioned / Linked · 2026-04-04: 1PoC Mentioned / Linked · 2026-04-05: 3PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-23: 1PoC Mentioned / Linked · 2026-05-04: 1Exploit Tool / Code · 2026-02-09: 1Exploit Tool / Code · 2026-03-30: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-04-01: 1Exploit Tool / Code · 2026-04-04: 1Active Exploitation · 2026-02-09: 1Active Exploitation · 2026-02-10: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-03-30: 25Active Exploitation · 2026-03-31: 16Active Exploitation · 2026-04-01: 12Active Exploitation · 2026-04-03: 4Active Exploitation · 2026-04-04: 4Active Exploitation · 2026-04-05: 4Active Exploitation · 2026-04-06: 15Active Exploitation · 2026-04-07: 9Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-04-10: 2Active Exploitation · 2026-04-13: 3Active Exploitation · 2026-04-14: 5Active Exploitation · 2026-04-15: 2Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-17: 2Active Exploitation · 2026-04-19: 2Active Exploitation · 2026-04-20: 2Active Exploitation · 2026-04-21: 2Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-05-08: 2Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-06-16: 1Active Exploitation · 2026-06-17: 1Patch / Workaround · 2026-02-06: 3Patch / Workaround · 2026-02-09: 3Patch / Workaround · 2026-02-10: 17Patch / Workaround · 2026-02-11: 7Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-30: 7Patch / Workaround · 2026-03-31: 7Patch / Workaround · 2026-04-01: 5Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-04: 4Patch / Workaround · 2026-04-05: 4Patch / Workaround · 2026-04-06: 9Patch / Workaround · 2026-04-07: 7Patch / Workaround · 2026-04-14: 2Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-17: 3Patch / Workaround · 2026-04-18: 2Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-24: 2Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-06-16: 2Patch / Workaround · 2026-08-11: 1Technical Details · 2026-02-06: 8Technical Details · 2026-02-09: 3Technical Details · 2026-02-10: 20Technical Details · 2026-02-11: 7Technical Details · 2026-02-14: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-23: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-17: 3Technical Details · 2026-03-18: 3Technical Details · 2026-03-19: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-28: 2Technical Details · 2026-03-30: 21Technical Details · 2026-03-31: 16Technical Details · 2026-04-01: 11Technical Details · 2026-04-03: 3Technical Details · 2026-04-04: 5Technical Details · 2026-04-05: 5Technical Details · 2026-04-06: 13Technical Details · 2026-04-07: 8Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 3Technical Details · 2026-04-14: 5Technical Details · 2026-04-15: 3Technical Details · 2026-04-16: 6Technical Details · 2026-04-17: 4Technical Details · 2026-04-18: 2Technical Details · 2026-04-19: 3Technical Details · 2026-04-20: 2Technical Details · 2026-04-21: 2Technical Details · 2026-04-24: 2Technical Details · 2026-04-27: 2Technical Details · 2026-05-01: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-17: 1Technical Details · 2026-08-11: 102-0602-1603-1103-1904-0104-0704-1404-1904-2705-1910-10
Signal classification6 categories
Active Exploitation
11951.5%
Patch
4720.3%
Disclosure
4218.2%
General
166.9%
PoC
62.6%
Exploit
10.4%
Referenced assets164 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-068
Disclosure8
2026-02-094
Exploit1General1Patch2
2026-02-1024
Disclosure5General2Patch17
2026-02-1110
Disclosure2General1Patch7
2026-02-141
Disclosure1
2026-02-161
Disclosure1
2026-02-191
Patch1
2026-02-231
Patch1
2026-02-251
Patch1
2026-03-102
Active Exploitation1Disclosure1
2026-03-111
Disclosure1
2026-03-131
PoC1
2026-03-141
General1
2026-03-173
Disclosure3
2026-03-183
Disclosure1Patch1PoC1
2026-03-191
Active Exploitation1
2026-03-261
Disclosure1
2026-03-282
Active Exploitation1Disclosure1
2026-03-3030
Active Exploitation23General4Patch2PoC1
2026-03-3120
Active Exploitation16Disclosure2General1PoC1
2026-04-0115
Active Exploitation12Disclosure2Patch1
2026-04-034
Active Exploitation4
2026-04-045
Active Exploitation4Patch1
2026-04-059
Active Exploitation4Disclosure2General2Patch1
2026-04-0615
Active Exploitation15
2026-04-0710
Active Exploitation8General1Patch1
2026-04-092
Active Exploitation1Disclosure1
2026-04-102
Active Exploitation2
2026-04-121
Disclosure1
2026-04-135
Active Exploitation3Disclosure2
2026-04-145
Active Exploitation5
2026-04-153
Active Exploitation2General1
2026-04-167
Active Exploitation1Disclosure3General1Patch1PoC1
2026-04-174
Active Exploitation2Patch2
2026-04-182
Patch2
2026-04-193
Active Exploitation2Patch1
2026-04-202
Active Exploitation2
2026-04-212
Active Exploitation2
2026-04-231
Disclosure1
2026-04-243
Active Exploitation1Disclosure1Patch1
2026-04-273
Active Exploitation2Patch1
2026-05-011
Disclosure1
2026-05-041
PoC1
2026-05-082
Active Exploitation2
2026-05-121
Patch1
2026-05-191
Active Exploitation1
2026-05-212
Disclosure1General1
2026-06-162
Active Exploitation1Patch1
2026-06-171
Active Exploitation1
2026-08-111
Patch1
Full discourse20 posts
  • Hunter@HunterMapping
    Active Exploitation

    🚨Alert🚨 CVE-2026-21643 (CVSS 9.1) : Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 🧐Detail : https://bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4 📊 4K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22FortiClient%20Endpoint%20Management%20Server%22 👇Query HUNTER : http://product.name="FortiClient Endpoint Management Server" 📰Refer:https://www.bleepingcomputer.com/news/security/critical-fortinet-forticlient-ems-flaw-now-exploited-in-attacks/ https://fortiguard.fortinet.com/psirt/FG-IR-25-1142 #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    CVE-2026-21643 is a high‑severity pre‑authentication SQL injection in FortiClient EMS 7.4.4 that is currently being exploited in the wild, with vendor advisory and patch information available.

    579133419420.4K
    25.9K followersView on X
  • Anastasis Vasileiadis@Anastasis_King
    Active Exploitation

    🚨 Bug Bounty / Red Team Tip CVE-2026-21643 — Critical Pre-Auth SQL Injection (CVSS 9.1) in FortiClient EMS 7.4.4 (multi-tenant mode only) Unauthenticated attackers can inject arbitrary SQL via the Site HTTP header to the public endpoint /api/v1/init_consts (or login endpoint). This happens before authentication and hits the PostgreSQL backend with superuser-level access in many setups → full DB dump, schema extraction, or RCE (via PostgreSQL features like COPY FROM PROGRAM). - Affected: Only FortiClient EMS 7.4.4 (multi-tenant/Sites feature enabled) - Not affected: 7.2.x, 8.0.x, single-site deployments - Fixed: Upgrade to 7.4.5 or later - Status: Actively exploited in the wild + public PoCs available Main Detail Article (Highly Recommended): Bishop Fox deep-dive with exploitation paths, payloads (e.g., pg_sleep(5) for blind testing), and lab results → https://bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4 Public PoC (GitHub): https://github.com/0xBlackash/CVE-2026-21643 Useful Google/Shodan Dorks: - http.title:"FortiClient EMS" "7.4.4" - http.html:"FortiClient Enterprise Management Server" - http.favicon.hash: -specific-hash (or search for EMS login page) - Shodan: "Model: FCTEMS" or "FortiClient EMS" Quick Check: If your EMS login page is internet-facing and running 7.4.4 with multi-tenant enabled → patch ASAP or block public access. Thousands of instances are exposed (Shadowserver ~2k+, Shodan ~1k+). High-value target for hunters. Patch or restrict immediately! #BugBounty #RedTeam #Fortinet #CVE202621643 #SQLi

    Post summary

    CVE-2026-21643 is a critical pre-auth SQL injection in FortiClient EMS 7.4.4, actively exploited in the wild with publicly available PoC code; upgrade to 7.4.5 or block internet-facing access immediately.

    257125813616.1K
    10.2K followersView on X
  • NullSecurityX@NullSecurityX
    Disclosure

    CVE-2026-21643 "FortiGhost" : Pre-Auth SQLi RCE in FortiClientEMS Useful Google/Shodan Dorks: - http.title:"FortiClient EMS" "7.4.4" - http.html:"FortiClient Enterprise Management Server" - http.favicon.hash: -specific-hash (or search for EMS login page) https://t.co/0N4zEqRNNX

    Post summary

    The post discloses CVE-2026-21643 as a pre‑authentication SQL injection that can lead to remote code execution in FortiClient EMS, and offers search queries to identify affected installations.

    150124812417.0K
    12.1K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🚨🛡️ Fortinet Fixes Critical FortiClientEMS RCE (CVE-2026-21643, CVSS 9.1). SQL injection flaw enables unauthenticated remote command execution via crafted requests. Affects EMS 7.4.4 (patch available). 🔗 See affected versions and patch guidance → https://thehackernews.com/2026/02/fortinet-patches-critical-sqli-flaw.html

    Post summary

    Fortinet released a patch for CVE‑2026‑21643, a critical SQL injection flaw in FortiClientEMS that could lead to unauthenticated remote command execution on version 7.4.4, with patch guidance provided via the linked article.

    55531422138.6K
    1.0M followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Fortinet Forticlient EMS CVE-2026-21643 - currently marked as not exploited on CISA and other Known Exploited Vulnerabilities (KEV) lists - has seen first exploitation already 4 days ago according to our data Attackers can smuggle SQL statements through the "Site"-header inside an HTTP request According to Shodan, close to 1000 instances of Forticlient EMS are publicly exposed. Track exploitation of this and other Fortinet honeypots 👉 https://console.defusedcyber.com/capabilities

    Post summary

    CVE‑2026‑21643 in Fortinet Forticlient EMS has been actively exploited, with attackers injecting SQL via the Site header; no patch or PoC details are provided.

    1304685441.8K
    6.7K followersView on X
  • Rishi@rxerium
    Active Exploitation

    🚨 CVE-2026-21643 an SQL Injection vulnerability (CVSS 9.8) is seeing active exploitation in the wild as reported by @DefusedCyber Vulnerability detection script available here: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-21643.yaml This vulnerability currently only affects FortiClientEMS 7.4.4 and it is recommended that you upgrade to 7.4.5 or later as reported by Fortinet: https://fortiguard.fortinet.com/psirt/FG-IR-25-1142

    Post summary

    CVE-2026-21643 is a high‑severity SQL injection affecting FortiClientEMS 7.4.4 that is actively exploited in the wild; users should upgrade to 7.4.5 or later or apply vendor patches.

    1161783613.0K
    3.8K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    ⚠️ Critical Fortinet FortiClient EMS Vulnerability Exploited in Attacks Source: https://cybersecuritynews.com/forticlient-ems-vulnerability-exploited/ A critical SQL injection vulnerability in Fortinet’s FortiClient Endpoint Management Server (EMS), tracked as CVE-2026-21643, is actively being exploited in the wild. In observed attacks, threat actors are bypassing security controls by smuggling malicious SQL statements through the Site header within an HTTP GET request. A recorded payload targeting the /api/v1/init_consts endpoint demonstrates attackers injecting commands such as Site: x'; SELECT pg_sleep(4)--. This specific attack was observed originating from the threat actor IP address 104.192.92[.]135. #cybersecuritynews #vulnerability

    Post summary

    CVE-2026-21643 is a critical SQL injection flaw in Fortinet FortiClient EMS that is being actively exploited in the wild, as attackers inject SQL through the Site header, but the post lacks any PoC, exploitation code, or patch information.

    318066144.4K
    65.9K followersView on X
  • Cristian Borghello@SeguInfo
    General

    Como diría alguien (de #Fortinet): "que MAL que la estoy pasando"😤 - CVE-2026-21643 - Inyección SQL (9.1) - CVE-2026-35616 - Control de acceso inadecuado (9.1) - CVE-2026-39808 - Ejecución de comandos (9.1) 🔗https://blog.segu-info.com.ar/2026/04/otra-vulnerabilidad-critica-rce-en.html PARCHEA!

    Post summary

    The blog post lists three critical CVEs with corresponding vulnerability types but offers no concrete exploitation, mitigation, or patch details.

    012038152.9K
    38.3K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    Heads up FortiClient EMS users! CVE-2026-35616 (new) & CVE-2026-21643 - both unauthenticated RCE observed to be exploited in the wild! We fingerprint about 2000 instances globally, see public Dashboard: https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=30&vendor=fortinet&model=forticlient+enterprise+management+server+%28ems%29&dataset=count&limit=100&group_by=geo&stacking=stacked&auto_update=on Top affected: US & Germany https://dashboard.shadowserver.org/statistics/iot-devices/map/?date_range=1&vendor=fortinet&model=forticlient+enterprise+management+server+%28ems%29&data_set=count&scale=log&auto_update=on https://t.co/tLOs6mhgBk

    Post summary

    FortiClient EMS users are warned that CVE-2026-35616 and CVE-2026-21643—unauthenticated remote code execution flaws—are being actively exploited worldwide, with over 2,000 instances detected, mainly in the US and Germany.

    114133158.5K
    21.8K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-21643 (CVSS 9.8): Pre-auth SQL injection in FortiClient EMS 7.4.4 may allow unauthorized code or command execution via crafted HTTP requests. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJGb3J0aUNsaWVudC1FTVMi 🎯2.8K+ Results are found on http://en.fofa.info. FOFA Query: app="FortiClient-EMS" 🔖Refer: https://nvd.nist.gov/vuln/detail/CVE-2026-21643 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE‑2026‑21643 is a high‑severity pre‑authentication SQL injection in FortiClient EMS 7.4.4, potentially allowing remote code execution via crafted HTTP requests; the post references FOFA search results and the NVD entry.

    14036152.5K
    14.3K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Two updates from the Defused honeypot lab 1️⃣ New FortiClient EMS decoy deployed CVE-2026-21643 (pre-auth SQLi, CVSS 9.1) - Bishop Fox just dropped a full exploitation writeup for FortiClient EMS 7.4.4. No public exploitation observed yet but with a detailed writeup now out, it's a matter of time. We've added a FortiClient EMS honeypot stream to catch early exploitation attempts 🍯 2️⃣ SharePoint CVE-2026-20963 added to CISA KEV Microsoft SharePoint deserialization flaw - actively exploited in the wild. RCE via crafted network requests, no auth required. Track exploitation attempts against our SharePoint decoys on the platform. 👉 http://console.defusedcyber.com/signup

    Post summary

    The update announces a full exploitation writeup for a FortiClient EMS SQLi vulnerability and confirms that the SharePoint deserialization flaw is being actively exploited in the wild.

    1922664.1K
    6.2K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    6 ثغرات تهدد اغلب الاجهزة والشبكات يتم استغلالها حاليا 🚨 CISA أضافت 6 ثغرات جديدة لقائمة (KEV)Known Exploited Vulnerabilities بعد تأكد الاستغلال الفعلي لها حاليا من قبل المخترقين. الثغرة CVE-2026-21643 (CVSS: 9.1) 🔴 المنتج: FortiClient EMS من Fortinet النوع: SQL Injection التأثير: تنفيذ كود خبيث بدون مصادقة الحالة: استغلال مؤكد منذ 24 مارس 2026 الثغرة CVE-2020-9715 (CVSS: 7.8)🟠 المنتج: Adobe Acrobat Reader النوع: Use-After-Free التأثير: Remote Code Execution ثغرة تستغل من (2020) ولكن تم اكتشافها والاعلان عنها مؤخرا الثغرة CVE-2023-36424 (CVSS: 7.8) 🟠 المنتج: Microsoft Windows Common Log File System Driver النوع: Out-of-Bounds Read التأثير: Privilege Escalation ما فيه تقارير استغلال علنية، بس CISA تؤكد انها تتسغل حاليا . الثغرة CVE-2023-21529 (CVSS: 8.8) 🔴 المنتج: Microsoft Exchange Server النوع: Deserialization of Untrusted Data التأثير: Remote Code Execution المجموعة الصينية Storm-1175 تستغلها لـ Medusa Ransomware. الثغرة CVE-2025-60710 (CVSS: 7.8)🟠 المنتج: Host Process for Windows Tasks النوع: Improper Link Resolution Before File Access التأثير: Local Privilege Escalation الثغرة CVE-2012-1854 (CVSS: 7.8) 📅🟠 المنتج: Microsoft Visual Basic for Applications (VBA) النوع: Insecure Library Loading التأثير: Remote Code Execution ثغرة من 2012! Microsoft عمرها ١٤ سنه ولاتزال تستغل

    Post summary

    The post announces that six CVEs are being actively exploited, as confirmed by CISA’s KEV list, and provides detailed technical information for each vulnerability without offering patches or code.

    16020152.6K
    49.2K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    [Blog] Explotación activa de una inyección SQL crítica en Fortinet FortiClient EMS (CVE-2026-21643) https://blog.elhacker.net/2026/04/explotacion-activa-de-una-inyeccion-sql.html

    Post summary

    CVE-2026-21643, a critical SQL injection in Fortinet FortiClient EMS, is being actively exploited in the wild as indicated by the blog title.

    01102832.3K
    140.8K followersView on X
  • Cristian Borghello@SeguInfo
    Active Exploitation

    (Otra) Vulnerabilidad SQLi está siendo explotada en Fortinet FortiClient EMS (CVE-2026-21643) http://blog.segu-info.com.ar/2026/03/otra-vulnerabilidad-sqli-esta-siendo.html

    Post summary

    The post reports that the SQL injection flaw CVE-2026-21643 in Fortinet FortiClient EMS is actively being exploited, but provides no PoC, exploit code, patch, or false-positive information.

    0802762.3K
    38.3K followersView on X
  • Dark Web Informer@DarkWebInformer
    General

    ‼️ CVE-2026-21643 detection script for FortiClientEMS 7.4.4. 👇

    Post summary

    The post cites a detection script for CVE-2026-21643 on FortiClientEMS 7.4.4 but offers no additional exploit, mitigation, or technical details.

    1701867.1K
    218.4K followersView on X
  • siri@fu4k1@sirifu4k1
    PoC

    Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 - CVE-2026-21643 #cve #poc #sqli https://bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4

    Post summary

    The message announces a pre‑authentication SQL injection (CVE‑2026‑21643) in FortiClient EMS 7.4.4, shares a link hinting at a proof‑of‑concept, and provides basic technical details.

    11001451.3K
    6.9K followersView on X
  • watchTowr@watchtowrcyber
    Disclosure

    Rapid reaction gets you ahead. 67 days before CISA added CVE-2026-21643 (Fortinet FortiClientEMS SQL Injection) to KEV, watchTowr clients were aware of their exposure. Reach out via our website if you need support. https://t.co/wUcr9152hJ

    Post summary

    watchTowr warned its clients about CVE‑2026‑21643 67 days before CISA listed it on KEV, providing early exposure awareness without offering a PoC, exploit code, or patch details.

    1201762.8K
    12.1K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Bishop Fox publicly disclosed details of a critical 9.1 CVSS zero-click SQL injection in FortiClient EMS (CVE-2026-21643). Patch to 7.4.5 immediately. #FortiClient #CVE #SQLInjection #CyberSecurity #InfoSec #BishopFox #ZeroClick #Vulnerability #TechNews https://securityonline.info/publicly-disclosed-critical-zero-click-sql-injection-forticlient-ems-cve-2026-21643/ https://t.co/ik3TZ9xhPd

    Post summary

    Bishop Fox disclosed a zero‑click SQL injection (CVE‑2026‑21643) in FortiClient EMS with a CVSS score of 9.1 and urged users to patch to version 7.4.5 immediately.

    0701421.1K
    10.7K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    [Blog] Vulnerabilidad SQLi está siendo explotada en Fortinet FortiClient EMS (CVE-2026-21643) https://blog.elhacker.net/2026/04/vulnerabilidad-sqli-esta-siendo.html

    Post summary

    The blog post announces that CVE-2026-21643, a SQL injection vulnerability in Fortinet FortiClient EMS, is currently being exploited.

    1601211.8K
    140.8K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Active Exploitation

    🛑 Fortinet 👉 CVE-2026-21643 : cette faille de sécurité critique présente dans FortiClient EMS commence à être exploitée par les cybercriminels. Le point à ce sujet 👇 - https://www.it-connect.fr/cve-2026-21643-cette-faille-critique-dans-forticlient-ems-est-exploitee/ #infosec #cybersecurite #fortinet https://t.co/jLNNq1vhbf

    Post summary

    The tweet claims CVE-2026-21643 is being actively exploited against FortiClient EMS, but provides no concrete evidence, PoC, or technical details.

    04091587
    11.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetforticlientems7.4.4--

Explore more