Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Updates Fix Major SQL Injection Vulnerability

Fortinet Updates Fix Major SQL Injection Vulnerability

Posted on February 10, 2026 By CWS

Fortinet has released vital security updates to rectify a serious vulnerability in FortiClientEMS that might allow unauthorized execution of code on affected systems. The flaw, identified as CVE-2026-21643, has been assigned a CVSS score of 9.1, indicating its critical nature.

Understanding the SQL Injection Flaw

This vulnerability arises from improper neutralization of special elements within an SQL command, commonly known as SQL injection, categorized under CWE-89. This flaw could potentially allow an unauthenticated attacker to run unauthorized code or commands by sending specially designed HTTP requests, according to Fortinet’s advisory.

Affected Software Versions

The vulnerability impacts specific versions of FortiClientEMS. Versions 7.4.4 require an upgrade to version 7.4.5 or higher to mitigate the threat. Versions 7.2 and 8.0 are not affected. The flaw was discovered by Gwendal Guégniaud from Fortinet’s Product Security team.

Immediate Action Recommended

Although there is no evidence of exploitation in the wild, Fortinet emphasizes the urgency for users to apply the released updates to safeguard their systems. Ignoring these updates could leave systems vulnerable to potential attacks exploiting the flaw.

Recently, Fortinet addressed another critical vulnerability in its FortiOS, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb products. This flaw, identified as CVE-2026-24858 with a CVSS score of 9.4, allowed attackers with access to FortiCloud accounts to log into other registered devices if FortiCloud SSO authentication was enabled.

Exploitation and Mitigation

Fortinet acknowledged that the latter vulnerability has been actively exploited by malicious actors. Attackers used this access to create local admin accounts, alter configurations to grant VPN access, and extract firewall configurations. This underscores the importance of promptly applying security patches to prevent similar breaches.

In conclusion, maintaining updated security measures is crucial to protect against such vulnerabilities. Fortinet’s prompt action in releasing these updates highlights the importance of staying vigilant and proactive in cybersecurity practices.

The Hacker News Tags:CVE-2026-21643, Cybersecurity, FortiClientEMS, FortiManager, Fortinet, FortiOS, network security, security updates, SQL injection, vulnerability patch

Post navigation

Previous Post: Revolutionary Open-source LLM Vulnerability Scanner Launched
Next Post: Chinese Cyber Espionage Targets Singapore Telecom Industry

Related Posts

Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp The Hacker News
Alert Fatigue, Data Overload, and the Fall of Traditional SIEMs Alert Fatigue, Data Overload, and the Fall of Traditional SIEMs The Hacker News
Key Features to Evaluate AI SOC Platforms in 2026 Key Features to Evaluate AI SOC Platforms in 2026 The Hacker News
New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea The Hacker News
Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access The Hacker News
ShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Miners ShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Miners The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • JetBrains Fixes Critical Security Flaws in Key Products
  • Dutch Police Break Up €100 Million Fraud Network
  • AI Security Testing Evolves with New Threats
  • Daxin Malware Reappears in Taiwan with New Stupig Backdoor
  • Next.js Enhances Security with Monthly Update Program

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • JetBrains Fixes Critical Security Flaws in Key Products
  • Dutch Police Break Up €100 Million Fraud Network
  • AI Security Testing Evolves with New Threats
  • Daxin Malware Reappears in Taiwan with New Stupig Backdoor
  • Next.js Enhances Security with Monthly Update Program

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark