CVE-2026-21643
CVE-2025-52436, with a CVSS score of 8.8 (High), is an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FortiSandbox which may allow an unauthenticated attacker to execute commands via crafted requests. CVE-2026-22153, having a CVSS score of 8.1, is an Authentication Bypass by Primary Weakness vulnerability in FortiOS fnbamd. Its exploitation may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. CVE-2025-68686, with a CVSS score of 5.9, is an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in FortiOS SSL-VPN which may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. UPDATE (2026-07-28) CISA added CVE-2025-68686 to its KEV list indicating active exploitation. The critical vulnerability previously patched, CVE-2026-21643, is an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS which may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
EPSS 94.09% · 99.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| FortiClientEMS | FortiClientEMS 7.4.4 | |
| FortiOS | FortiOS 7.6.0 through 7.6.4 | |
| FortiAuthenticator | FortiAuthenticator 6.4 all versions | |
| FortiAuthenticator | FortiAuthenticator 6.6.0 through 6.6.6 | |
| Microsoft | FortiClientWindows 7.0 all versions | |
| Microsoft | FortiClientWindows 7.4.0 through 7.4.4 | |
| FortiOS | FortiOS 7.4.0 through 7.4.9 | |
| FortiAuthenticator | FortiAuthenticator 6.5 all versions | |
| FortiSandbox | FortiSandbox 5.0.0 through 5.0.1 | |
| FortiOS | FortiOS 7.4.0 through 7.4.6 | |
| FortiOS | FortiOS 6.4 all versions | |
| FortiAuthenticator | FortiAuthenticator 6.3 all versions | |
| FortiSandbox | FortiSandbox 4.0 all versions | |
| FortiSandbox | FortiSandbox 4.4.0 through 4.4.7 | |
| Microsoft | FortiClientWindows 7.2.0 through 7.2.12 | |
| Fortinet | Fortinet FortiClientEMS 7.4.4 | |
| FortiOS | FortiOS 7.2 all versions | |
| FortiOS | FortiOS 7.0 all versions | |
| FortiOS | FortiOS 7.2.0 through 7.2.11 | |
| FortiSandbox | FortiSandbox 4.2 all versions |
Timeline
- May 14, 2021 CrowdSec Sighting
- Dec 29, 2021 CrowdSec Sighting
- Mar 9, 2023 CrowdSec Sighting
- Apr 5, 2023 CrowdSec Sighting
- Apr 9, 2023 CrowdSec Sighting
- May 14, 2023 CrowdSec Sighting
- Aug 10, 2023 CrowdSec Sighting
- May 21, 2024 CrowdSec Sighting
- May 30, 2024 CrowdSec Sighting
- May 30, 2024 CrowdSec Sighting
- May 30, 2024 CrowdSec Sighting
- May 31, 2024 CrowdSec Sighting
References
- https://ccb.belgium.be/advisories/warning-forticlient-ems-sql-injection-cve-2026-21643-patch-immediately advisory
- https://fortiguard.fortinet.com/psirt/FG-IR-25-1142 vendor
- https://bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4 technical
- https://www.helpnetsecurity.com/2026/03/30/forticlient-ems-cve-2026-21643-reported-exploitation/ technical
- https://www.cve.org/CVERecord?id=CVE-2026-21643 technical
- Nuclei Template exploit
- https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-were-patched-fortinet-products-patch-immediately advisory
- https://fortiguard.fortinet.com/psirt technical
- https://www.fortiguard.com/psirt/FG-IR-25-661 technical
- https://www.fortiguard.com/psirt/FG-IR-25-384 technical
- https://www.fortiguard.com/psirt/FG-IR-25-795 technical
- https://www.fortiguard.com/psirt/FG-IR-25-1052 technical
- https://www.fortiguard.com/psirt/FG-IR-25-528 technical
- https://www.fortiguard.com/psirt/FG-IR-25-667 technical
- https://www.fortiguard.com/psirt/FG-IR-25-934 technical
- https://www.fortiguard.com/psirt/FG-IR-25-093 technical
- https://www.fortiguard.com/psirt/FG-IR-25-1142 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-22153 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21743 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21643 technical
…and 6 more