A new worrying development in the cybersecurity space is bringing Fortinet’s FortiClient EMS platform to the forefront , as attackers have already begun actively exploiting a critical vulnerability . The security flaw, documented as CVE-2026-21643 , concerns an SQL injection vulnerability and allows unauthorized users to execute arbitrary commands on vulnerable systems via malicious HTTP requests.

How the attack works and why it is dangerous
This vulnerability exploits weaknesses in the input handling of the FortiClient EMS web interface. Attackers can pass malicious SQL commands via the 'Site'-header, gaining access to the database and, by extension, control of the system. The most worrying aspect is that the attack is characterized by low complexity, which makes it accessible even to less experienced cybercriminals.
See also: Citrix NetScaler: Vulnerability used in reconnaissance activities
First indications of exploitation before official confirmation
While the vulnerability has not yet been officially reported as being actively exploited by organizations like CISA, data from Defused shows that attacks have already begun in the past few days. The delay in official confirmation creates a dangerous “window” where organizations may underestimate the threat and delay implementing fixes.
Thousands of exposed systems on the internet
The scale of the problem is significant, as thousands of FortiClient EMS installations remain exposed to the internet. According to data from Shadowserver and the Shodan, more than 2,000 instances have publicly accessible web interfaces, with a large percentage of these located in the United States and Europe. This exposure dramatically increases the attack surface and makes it easier for attackers to identify vulnerable targets.
See also: Smart Slider 3 WordPress: Vulnerability affects thousands of sites
The importance of immediate information and available solutions
Fortinet has already released a patch, with the move to version 7.4.5 or later considered essential to protect systems. However, the delay in installing patches by many organizations remains a perennial problem, which often leads to successful attacks. Experts emphasize that upgrading immediately is not just a recommendation, but a critical defensive action.

Fortinet vulnerability exploitation history
This new vulnerability is not an isolated incident. Fortinet products have repeatedly been targeted by attacks, often in ransomware or cyberespionage campaigns . In many cases, attackers exploit zero-day vulnerabilities before patches are even released, taking advantage of the time gap between discovery and patching.
From ransomware attacks to cyber espionage
Of particular interest is the fact that such vulnerabilities are being used not only for financial gain, but also for strategic purposes. Attacks attributed to state-sponsored groups have targeted telecommunications providers and critical infrastructure, exploiting similar security gaps. The connection between commercial attacks and geopolitical motives makes the threat even more complex.
See also: Hackers exploit critical RCE flaw in Langflow
The bigger picture: Continued pressure on enterprise platforms
This incident highlights the ongoing pressure on enterprise endpoint management and security solutions. Platforms like FortiClient EMS sit at the core of corporate infrastructure, making them particularly attractive targets. A successful attack can provide complete visibility and control over a corporate network, with devastating consequences.

The need for proactive cybersecurity
The CVE-2026-21643 vulnerability is yet another wake-up call for businesses that rely on critical security platforms. Given that exploitation has already begun, immediate action is essential. In an environment where threats are rapidly evolving, adopting proactive strategies, continuous monitoring, and timely application of updates are the only reliable line of defense against an increasingly aggressive digital landscape.
Source: www.bleepingcomputer.com
