A critical SQL injection vulnerability, CVE-2026-21643, has been identified in FortiClient Endpoint Management Server (EMS), a centralized management platform for FortiClient endpoint agents across multiple environments. The vulnerability is currently under active exploitation in the wild, even though it is not yet listed in major exploited vulnerability catalogs. Early attack activity indicates that threat actors […]
The post FortiClient EMS Under Fire: Critical CVE-2026-21643 Exploited in Real-World Attacks appeared first on SecPod Blog.