Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Fortinet FortiClientEMS SQL Injection Vulnerability Allowing Code Execution

Vulnerability

A SQL injection vulnerability has been identified in Fortinet FortiClientEMS version 7.4.4. This vulnerability arises from improper neutralization of special elements used in SQL commands, potentially allowing an unauthenticated attacker to execute unauthorized code or commands by sending specifically crafted HTTP requests.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on the server where Fortinet FortiClientEMS is running.

Added: Feb 6, 2026, 9:29 AM
Updated: Apr 13, 2026, 5:23 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
9.4
remediation
0.0
relevance
2.8
threat
9.3
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.