FAIL › dossier
FortiClient EMS
PRODUCT· dossier confidence 50%
FortiClient EMS, a network security management system, has experienced multiple high-severity vulnerabilities, including SQL injection, leading to arbitrary code execution and potential ransomware-linked breaches.
PROFILE
CategorySecurity SoftwareWhat they doFortiClient EMS is a network security management system designed to manage and secure endpoints on corporate networks.
SECURITY POSTURE
The company has faced multiple high and critical security vulnerabilities, indicating potential weaknesses in their product's security posture.
Notable failures
- CVE-2026-21643: Unauthenticated SQL injection leading to arbitrary code execution
- CVE-2026-35616: Unauthenticated crafted requests leading to arbitrary code execution
- CVE-2023-48788: Unauthenticated SQL injection leading to SYSTEM command execution and ransomware-linked breaches
Patterns: Repeated SQL injection vulnerabilities; Lack of proper authentication controls
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-04-13 | CVE-2026-21643 | high | Fortinet FortiClient EMS allows unauthenticated attackers to execute arbitrary code via SQL injection. |
| 2026-04-06 | CVE-2026-35616 | high | Fortinet FortiClient EMS allows unauthenticated attackers to execute arbitrary code via crafted requests. |
| 2024-03-25 | CVE-2023-48788 | critical | An unauthenticated SQL injection in Fortinet FortiClient EMS allowed attackers to execute SYSTEM commands, leading to ransomware-linked breaches. |
Open questions: How has Fortinet addressed these vulnerabilities? · What is the current state of security for FortiClient EMS?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:45:14.610670+00:00