DefectiveCISO on Nostr: forticlient ems letting sql through the site header, exploited before cisa even ...
forticlient ems letting sql through the site header, exploited before cisa even blinks. another fortinet product reminding us why we patch those things first.
> Fortinet Forticlient EMS CVE-2026-21643 - currently marked as not exploited on CISA and other Known Exploited Vulnerabilities (KEV) lists - has seen first exploitation already 4 days ago according to our data
>
> Attackers can smuggle SQL statements through the "Site"-header
— @DefusedCyber
#cybersecurity #infosec #news #vulnerability
https://x.com/DefusedCyber/status/2037912573274636781Published at
2026-03-28 17:49:23 UTCEvent JSON
{
"id": "1775808b30101743ad3a486bf6c1b005e39571e14c6d802b47da38aa32fd2fad",
"pubkey": "c515131657f13f4486cff1b6078a0f2ad3d083acd0c2bf46b192a33f8f80efc8",
"created_at": 1774720163,
"kind": 1,
"tags": [
[
"imeta",
"url https://image.nostr.build/357323a19fc301ea3065791331a1f14047aa2aed58e76370e1cbcc7a9db516de.jpg"
],
[
"t",
"cybersecurity"
],
[
"t",
"infosec"
],
[
"t",
"news"
],
[
"t",
"vulnerability"
],
[
"r",
"https://x.com/DefusedCyber/status/2037912573274636781"
],
[
"source",
"x.com"
]
],
"content": "forticlient ems letting sql through the site header, exploited before cisa even blinks. another fortinet product reminding us why we patch those things first.\n\n\u003e Fortinet Forticlient EMS CVE-2026-21643 - currently marked as not exploited on CISA and other Known Exploited Vulnerabilities (KEV) lists - has seen first exploitation already 4 days ago according to our data\n\u003e \n\u003e Attackers can smuggle SQL statements through the \"Site\"-header\n— @DefusedCyber\n\nhttps://image.nostr.build/357323a19fc301ea3065791331a1f14047aa2aed58e76370e1cbcc7a9db516de.jpg\n\n#cybersecurity #infosec #news #vulnerability\nhttps://x.com/DefusedCyber/status/2037912573274636781",
"sig": "d88dd33851652b3602017d4b74c59683d821adce07a7eb7ffd4ed87797a3d038a913581e20249e0896f9d6b524e1f72af884c34e4ac1ace10afc4b12da6cdde2"
}