HIGHVulnerability
Verified
Global

CISA KEV: Fortinet FortiClient EMS — Fortinet SQL Injection Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Analysis

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. Added to CISA Known Exploited Vulnerabilities catalog on 2026-04-13. Remediation due: 2026-04-16.

Indicators of Compromise (1)

CVE (1)
CVE-2026-21643
Source Attribution

Originally published by CISA KEV on Apr 13, 2026. Verified by: CISA.

Related Threats