CVE-2026-35616 & CVE-2026-21643 – Fortinet FortiClientEMS: Overview & Takeaways
netspi.com | vulnerability | #rce | #sqli | #cve-2026-35616 | #fortinet | #cve-2026-21643 | #in-the-wild | #auth-bypass | #forticlientems
Summary
Two actively exploited FortiClientEMS flaws: CVE-2026-35616, an unauthenticated API auth bypass to RCE in 7.4.5/7.4.6, and CVE-2026-21643, SQLi limited to 7.4.4 multi-tenant deployments.
- Published
- Collected
Skip to content