Close Menu
    What's Hot

    Who Can Vote for Mayor of Los Angeles?

    Russia Launches Massive Attack on Ukraine

    What to Know About South Korea’s Elections

    Facebook X (Twitter) Instagram
    Trending
    • Who Can Vote for Mayor of Los Angeles?
    • Russia Launches Massive Attack on Ukraine
    • What to Know About South Korea’s Elections
    • U.S. Treasury Imposes Sanctions on Iran’s Biggest Crypto Exchange
    • New Microsoft tool lets devs spin up AI behavior tests using text descriptions
    • NIQ Global Intelligence plc (NIQ) Presents at 2026 Baird Global Consumer, Technology & Services Conference Transcript
    • Liverpool reach agreement to name Andoni Iraola new coach – sources
    • MLB home run picks, odds: Nick Kurtz among best bets for June 2
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution

    adminBy adminFebruary 15, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananFeb 10, 2026Vulnerability / Network Security

    Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution

    Fortinet has released security updates to address a critical flaw impacting FortiClientEMS that could lead to the execution of arbitrary code on susceptible systems.

    The vulnerability, tracked as CVE-2026-21643, has a CVSS rating of 9.1 out of a maximum of 10.0.

    “An improper neutralization of special elements used in an SQL Command (‘SQL Injection’) vulnerability [CWE-89] in FortiClientEMS may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests,” Fortinet said in an advisory.

    The shortcoming affects the following versions –

    • FortiClientEMS 7.2 (Not affected)
    • FortiClientEMS 7.4.4 (Upgrade to 7.4.5 or above)
    • FortiClientEMS 8.0 (Not affected)
    Cybersecurity

    Gwendal Guégniaud of the Fortinet Product Security team has been credited with discovering and reporting the flaw.

    While Fortinet makes no mention of the vulnerability being exploited in the wild, it’s essential that users move quickly to apply the fixes.

    The development comes as the company addressed another critical severity flaw in FortiOS, FortiManager, FortiAnalyzer, FortiProxy, FortiWeb (CVE-2026-24858, CVSS score: 9.4) that allows an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

    Fortinet has since acknowledged that the issue has been actively exploited by bad actors to create local admin accounts for persistence, make configuration changes granting VPN access to those accounts, and exfiltrate the firewall configurations.

    Code critical Enabling Execution flaw Fortinet Patches SQLi Unauthenticated
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleHow to Make Sure You See Moose on an Alaska Cruise
    Next Article My uncanny AI valentines | The Verge
    admin
    • Website

    Related Posts

    Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

    June 2, 2026

    Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

    June 2, 2026

    How Leading Organizations Are Turning EDR Into Operational Resilience

    June 2, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Who Can Vote for Mayor of Los Angeles?

    Russia Launches Massive Attack on Ukraine

    What to Know About South Korea’s Elections

    U.S. Treasury Imposes Sanctions on Iran’s Biggest Crypto Exchange

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by