INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Fortinet FortiClient EMS Exploit Vulnerability Critical

| 2026-03-30 10:43 CRITICAL HIGH
Executive Summary AI-generated
Attackers are exploiting a critical Fortinet FortiClient EMS flaw (CVE-2026-21643) that allows remote code execution via SQL injection. The vulnerability, tracked as 9.1 on the CVSS scale, has been actively exploited since March 30th and is now being used to smuggle SQL statements through the "Site" header in HTTP requests. This could enable attackers to gain an initial foothold in a target network, allowing lateral movement or malware deployment. The vulnerability affects FortiClient EMS versions 7.4 and above, with affected software identified as FortinetFortiClientEMS 8.0 not being impacted but rather upgraded to version 7.4.5 or higher.
Technical Mitigations AI-generated
* Upgrade to FortiClientEMS 7.4.5 or later: This is the recommended solution to patch the vulnerability and prevent exploitation. * Use a web application firewall (WAF): Implementing a WAF can help block malicious traffic and reduce the risk of successful attacks. * Implement network segmentation: Segmenting your network into smaller, isolated areas can make it more difficult for attackers to spread their malware or exploit vulnerabilities in FortiClient EMS. * Use secure protocols: Ensure that all communication between devices is encrypted using HTTPS (Hypertext Transfer Protocol Secure) and other secure protocols.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon CVE-2023-48788CVE-2023-48788 CVE-2026-24858CVE-2026-24858 CVE-2026-21643CVE-2026-21643
Target & Sectors
EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA
Incident Timeline
March 2024
Threat actors exploited a FortiClient EMS SQL injection vulnerability tracked as CVE-2023-48788 to breach telecommunications service providers.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution CVE-2023-48788
tactic Ransomware
threat_actor Salt Typhoon
source_region China
organisation SecurityAffairs
2026-03-26
Threat actors exploited CVE-2026-21643 in Fortinet Forticlient EMS to execute remote code.
vulnerability CVE-2026-21643
attribution Fortinet Forticlient EMS CVE-2026-21643
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Forticlient EMS
general_metric 1000 instances
2026-03-30
Attackers are exploiting a critical Fortinet FortiClient EMS flaw (CVE-2026-21643) that allows remote code execution via SQL injection.
organisation Critical Fortinet FortiClient EMS
organisation Fortinet FortiClient EMS
organisation SQL
organisation FortiClient EMS
infrastructure 8.0
infrastructure 7.4
infrastructure 7.4.4
infrastructure 7.4.5
infrastructure 7.2
financial 683 Europe
organisation Shadowserver
victims 2,000 FortiClient EMS
infrastructure 1,400 IPs
organisation Fortinet’s FortiClient EMS
organisation an SQL Command
organisation Shodan
organisation FortiCloud SSO
organisation Fortinet
Tactical Metrics
Metrics
infrastructure
​8.0
Software Version
Metrics
infrastructure
​7.4
Software Version
Metrics
infrastructure
​7.4.4
Software Version
Metrics
infrastructure
​7.4.5
Software Version
Metrics
infrastructure
​7.2
Software Version
Metrics
financial
683
Europe
Metrics
victims
2,000
Forticlient Ems
Metrics
infrastructure
1,400
Ips
Intelligence Sources