🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Fortinet FortiClient EMS SQL Injection RCE (CVE-2026-21643) | MSSP Advisory

Critical🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2026-21643
📋Executive Summary
CISA flagged a SQL injection vulnerability in Fortinet FortiClient EMS that allows unauthenticated remote code execution through HTTP requests. The vulnerability targets endpoint management infrastructure that MSSPs commonly deploy across client environments.
⚠️Why It Matters for MSSPs
Your own FortiClient EMS installations become direct attack vectors for threat actors seeking MSSP network access. Every client environment running FortiClient EMS represents an advisory obligation since unauthenticated RCE means complete endpoint control without credentials.
Recommended Action
Audit all FortiClient EMS deployments across your stack and client environments within 24 hours. Apply Fortinet patches immediately where available or prepare client communications about service disruption if systems must be taken offline.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.