Fortinet has released security updates to address a critical vulnerability affecting FortiClientEMS that could lead to code execution on vulnerable systems.

The vulnerability, tracked as CVE-2026-21643, has a CVSS score of 9.1/10.
“ An improper neutralization of special elements used in a SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS could allow an unauthenticated attacker to execute arbitrary code or commands via specially crafted HTTP requests ,” Fortinet said in an advisory
See also: BeyondTrust patches critical RCE vulnerability in Remote Support and PRA
Fortinet FortiClientEMS: Which versions are affected?
– FortiClientEMS 7.2 (Not affected)
– FortiClientEMS 7.4.4 (Upgrade to 7.4.5 or later)
– FortiClientEMS 8.0 (Not affected)
Gwendal Guégniaud from Fortinet's Product Security team has been credited with discovering and reporting the vulnerability.
See also: Six new vulnerabilities discovered in the n8n automation platform

Although Fortinet does not report active exploitation of the vulnerability, it is essential that users move quickly to apply the fixes. Cybercriminals are not wasting time.
This development comes as the company addressed another critical vulnerability in FortiOS, FortiManager, FortiAnalyzer, FortiProxy, FortiWeb (CVE-2026-24858, CVSS score: 9.4) that allows an attacker with a FortiCloud account and registered device to log in to other devices that are associated with other accounts. This is possible if FortiCloud SSO authentication is enabled on those devices.
See also: Four new vulnerabilities in Ingress NGINX

This vulnerability has been actively exploited by malicious users to create local administrator accounts for persistence, make configuration changes that allow VPN access to these accounts, and export firewall configurations.
