← All CVEs NewScan detects
critical

CVE-2026-21643

FortiClient EMS 7.4.4 pre-authentication SQL injection in the management server

Severity
critical
Affected product
FortiClient EMS
Affected versions
FortiClient EMS all versions before the fix
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the FortiClient EMS appliance and reports this CVE when the detected version falls inside the affected range below.

Exploited in the wild alongside CVE-2026-35616. fuzz_parameter / test_blind_sqli cover SQLi generically, but a pre-auth appliance path needs this row to be probed.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →