An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Is CVE-2026-21643 exploited?
Listed in the CISA KEV catalog on 2026-04-13.
Federal remediation due 2026-04-16.
Past that date by 121 days.
EPSS puts exploitation in the next 30 days at 94%.
Public exploit code: none found in monitored sources.