Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryendpoint-software-vulnerability

Unauthenticated RCE in FortiClient EMS via SQL Injection (CVE-2026-21643)

Updated 3mo agoFirst seen Feb 9, 20266 sources

Fortinet issued a critical advisory for FortiClient Enterprise Management Server (EMS) warning that CVE-2026-21643 enables unauthenticated remote code execution via an SQL injection flaw (CWE-89) in the product’s GUI/web interface. By sending specially crafted HTTP requests that exploit insufficient input sanitization, an external attacker could execute arbitrary code or unauthorized commands on the EMS server without valid credentials, potentially turning a central endpoint-management platform into a foothold for broader compromise.

The issue is reported as affecting the 7.4 line, with FortiClientEMS 7.4.4 explicitly called out as vulnerable; Fortinet’s recommended remediation is to upgrade to 7.4.5 or later. Fortinet also stated that the 8.0 and 7.2 branches are not affected, and an updated note indicated FortiEMS Cloud/SaaS instances are not impacted, narrowing immediate exposure primarily to on-prem deployments running the affected version.

Share:
Unauthenticated RCE in FortiClient EMS via SQL Injection (CVE-2026-21643)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 11, 20264mo ago

NCIIPC India flags CVE-2026-21643 as critical

By February 11, 2026, India's NCIIPC had flagged CVE-2026-21643 as a critical issue for OEM checks, reflecting broader government-sector awareness of the FortiClientEMS vulnerability. Reporting also reiterated that fixes had been available since February 6.

Feb 9, 20264mo ago

Public reporting notes no evidence of CVE-2026-21643 exploitation

As public coverage of the advisory spread, reports highlighted that Fortinet had not identified evidence of in-the-wild exploitation of CVE-2026-21643 at the time of publication. The company nevertheless urged rapid patching and review of logs for suspicious requests to the EMS GUI.

Canadian Centre for Cyber Security republishes Fortinet advisory

The Canadian Centre for Cyber Security issued alert AV26-096 referencing Fortinet's February 6 advisory for CVE-2026-21643, identifying FortiClientEMS 7.4.4 as affected and urging administrators to review the vendor guidance and apply updates. This amplified official notice of the vulnerability to Canadian defenders.

Feb 6, 20265mo ago

Fortinet clarifies FortiEMS Cloud is not affected

A February 6, 2026 advisory timeline update clarified that FortiEMS Cloud is unaffected by CVE-2026-21643. This narrowed the impact to affected on-premises FortiClientEMS deployments, specifically version 7.4.4.

Fortinet publishes advisory and patches CVE-2026-21643

On February 6, 2026, Fortinet published a high-priority security advisory for CVE-2026-21643, a critical SQL injection flaw in FortiClientEMS 7.4.4 that can enable unauthenticated remote code or command execution via crafted HTTP requests. Fortinet released a fix, advised customers to upgrade to version 7.4.5 or later, and stated that the 7.2 and 8.0 branches are not affected.

Jan 2, 20266mo ago

Fortinet internally discovers FortiClientEMS SQL injection flaw

Fortinet's Product Security team internally identified a critical SQL injection vulnerability in the FortiClientEMS administrative interface, later assigned CVE-2026-21643 and tracked by Fortinet as FG-IR-25-1142. Reporting attributes the discovery to Gwendal Guégniaud of the Fortinet Product Security team.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Affected products
6 linked
ForticlientemsFortianalyzerFortiproxyFortimanagerFortiosFortiweb
Organizations
3 linked
FortinetKasperskySecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Unauthenticated RCE in FortiClient EMS via SQL Injection (CVE-2026-21643) | Mallory