Join Nostr
2026-03-28 17:49:23 UTC

DefectiveCISO on Nostr: forticlient ems letting sql through the site header, exploited before cisa even ...

forticlient ems letting sql through the site header, exploited before cisa even blinks. another fortinet product reminding us why we patch those things first.

> Fortinet Forticlient EMS CVE-2026-21643 - currently marked as not exploited on CISA and other Known Exploited Vulnerabilities (KEV) lists - has seen first exploitation already 4 days ago according to our data
>
> Attackers can smuggle SQL statements through the "Site"-header
— @DefusedCyber



#cybersecurity #infosec #news #vulnerability
https://x.com/DefusedCyber/status/2037912573274636781