Known vulnerability record

CVE-2026-21643

Fortinet FortiClient EMS SQL Injection Vulnerability

Stable IDcve:CVE-2026-21643Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Keep the signals separate

CVSS severitycriticalScore 9.1 · source fortinet
EPSS probability94.1%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-04-13
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-02-06
CVE modified
2026-04-14
KEV date added
2026-04-13
Dataset fetched
2026-08-21T03:55:09.521Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.