LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-21643: Fortinet FortiClient EMS SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 13, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 16, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-21643 to its Known Exploited Vulnerabilities catalog on Apr 13, 2026, with a federal patch deadline of Apr 16, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute unauthorized code or commands through specifically crafted HTTP requests. This matters because successful exploitation can give an attacker direct control over the EMS instance and the endpoint management data it holds.

How it works

The weakness is categorized as CWE-89, improper neutralization of special elements used in an SQL command. In this class of flaw an attacker supplies input that alters the intended structure of a database query. For this product the input arrives in unauthenticated HTTP requests, allowing the attacker to cause the application to run commands or retrieve data outside the original query scope. Specific request formats and affected parameters are not provided here and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

FortiClient EMS is typically deployed as a central management server for Fortinet endpoint agents. Inventory all instances by checking network segments that host management consoles, reviewing installed software lists on Windows and Linux servers, and examining any cloud-hosted deployments. Confirm the exact versions and configurations in use against the vendor advisory, because not every release is affected. Review web server and application logs for anomalous HTTP requests that contain SQL syntax, unusual parameter values, or error responses that mention database queries. Telemetry from the EMS database itself may show unexpected query patterns if logging is enabled at that layer.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation. After patching, review and restrict network access to the EMS administrative interfaces so that only authorized management hosts can reach them. Disable or tightly control any exposed HTTP endpoints that accept unauthenticated input. Follow the vendor's hardening guidance for database access controls and input handling within the EMS application.

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to unauthorized access and subsequent data exposure in other environments. You can run a free exposure scan of your email addresses against known breach data to check for prior incidents involving your organization.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiClient EMS
WeaknessCWE-89
Added to CISA KEVApr 13, 2026
Federal patch deadlineApr 16, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities