Critical Fortinet FortiClient EMS vulnerability under attack
Overview
Researchers from Defused have reported ongoing attacks exploiting a serious SQL injection vulnerability in Fortinet's FortiClient EMS, identified as CVE-2026-21643. These intrusions have been active since March 24, raising concerns for organizations using this software. SQL injection vulnerabilities allow attackers to manipulate database queries, potentially leading to unauthorized access and data breaches. Companies utilizing FortiClient EMS are urged to take immediate action to protect their systems and data from these exploits. The situation emphasizes the need for regular security updates and vigilance against emerging threats.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Fortinet FortiClient EMS
- Action Required: Organizations should patch FortiClient EMS to the latest version as soon as possible.
- Timeline: Ongoing since March 24, 2026
Original Article Summary
Intrusions harnessing a critical SQL injection flaw in Fortinet FortiClient EMS, tracked as CVE-2026-21643, were reported by Defused researchers to have been ongoing since Mar. 24, according to Security Affairs.
Impact
Fortinet FortiClient EMS
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since March 24, 2026
Remediation
Organizations should patch FortiClient EMS to the latest version as soon as possible. Regularly monitor systems for unusual activity and implement web application firewalls to help filter malicious traffic. Conduct a review of database queries to ensure they are secure against SQL injection attacks.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Fortinet, Vulnerability, and 1 more.