Fortinet Releases Patch for Critical SQL Injection Flaw in FortiClientEMS
Fortinet has issued security updates to fix a critical SQL injection vulnerability (CVE-2026-21643) in FortiClientEMS that allows an unauthenticated attacker to send specially crafted HTTP requests and potentially execute arbitrary code or system commands on vulnerable servers, carrying a high severity score. Administrators are urged to immediately upgrade affected 7.4.4 installations to the patched version to prevent compromise, while the broader Fortinet ecosystem continues to face multiple recent serious flaws.
https://thehackernews.com/2026/02/fortinet-patches-critical-sqli-flaw.html
Comments
Post a Comment