Exploited in the wild FortiClient EMS network-edge Fortinet
Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 - CVE-2026-21643
TL;DR
Bishop Fox researchers expanded on Fortinet’s disclosure of CVE-2026-21643 by identifying practical exploitation paths. Our analysis shows attackers can abuse the publicly accessible
/api/v1/init_constsendpoint to trigger the SQL injection before authentication. Because this endpoint returns database error messages and has no lockout protections, attackers can rapidly extract sensitive data from vulnerable FortiClient EMS 7.4.4 multi-tenant deployments.…