๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-21643: Fortinet SQL Injection Vulnerability
Summary
Fortinet FortiClient EMS contains a SQL injection vulnerability (a flaw where attackers insert malicious database commands into input fields) that allows unauthenticated attackers to run unauthorized code through specially crafted web requests. This vulnerability is currently being exploited by real attackers in the wild.
Solution / Mitigation
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vulnerability Details
EPSS: 13.7%
Yes
๐ฅ Actively Exploited
April 12, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21643
First tracked: April 13, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%