Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution
To fix a serious vulnerability in FortiClientEMS that might let arbitrary code to run on vulnerable systems, Fortinet has published security upgrades.
Tracked as CVE-2026-21643, the vulnerability has a CVSS rating of 9.1 out of 10.0.
According to a Fortinet advisory, an unauthenticated attacker may be able to execute unauthorized code or commands via specially constructed HTTP requests due to an incorrect neutralization of special elements used in a SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS.
The shortcoming affects the following versions -
FortiClientEMS 7.2 (Not affected)
FortiClientEMS 7.4.4 (Upgrade to 7.4.5 or above)
FortiClientEMS 8.0 (Not affected)
Fortinet Product Security team member Gwendal Guégniaud is credited with identifying...







