Saturday , June 27 2026
Bishop Fox

ALERT
FortiClientEMS Vuln Let Attackers Execute Malicious Code Remotely

Fortinet has released a critical security advisory urging administrators to promptly update FortiClientEMS, its central management tool for endpoint protection.

A vulnerability, CVE-2026-21643, has a CVSSv3 score of 9.1 and may enable remote attackers to run unauthorized code on affected servers.

Hackers Target Cloudflare-Hosted AWS Domains to Steal Console Logins

A complex phishing attack targets AWS console users by misusing Cloudflare-hosted websites to steal login details. Each domain had a nearly...
Read More
Hackers Target Cloudflare-Hosted AWS Domains to Steal Console Logins

Daily Cyber security update for 26. 06. 2026

Cyberattacks are rising around the world, including ransomware, malware, data leaks, and hacked websites. These events show how complex and...
Read More
Daily Cyber security update for 26. 06. 2026

WhatsApp to Alert Users Before Chatting With New Numbers

WhatsApp is rolling a new security warning on Android and iOS. It shows up before users open a chat with...
Read More
WhatsApp to Alert Users Before Chatting With New Numbers

OpenAI unveils its first custom chip, Named Jalapeño

On Wednesday, OpenAI introduced its first special AI chip. This is aimed at growing from just consumer products to being...
Read More
OpenAI unveils its first custom chip, Named Jalapeño

Bajaj Auto System Hit by a Ransomware Attack

Bajaj Auto said on Tuesday that a ransomware attack impacted its systems and its subsidiary, Bajaj Auto Technology Ltd (BATL)....
Read More
Bajaj Auto System Hit by a Ransomware Attack

Cisco Unified CM flaw CVE-2026-20230 exploited in attacks

A serious SSRF flaw, called CVE-2026-20230, in Cisco Unified Communications Manager Server is now being used in attacks. Cisco put out...
Read More
Cisco Unified CM flaw CVE-2026-20230 exploited in attacks

LastPass says hackers stole customer data via Klue, supply chain breach

LastPass has reported a security issue with its vendor, Klue. This incident allowed an attacker unauthorized access to customer data....
Read More
LastPass says hackers stole customer data via Klue, supply chain breach

New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

Researchers at cybersecurity firm Paradigm Shift found a new flaw called usbliter8. This flaw can get around main boot protections...
Read More
New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

The flaw is categorized as an SQL Injection (SQLi) vulnerability, formally identified as an “improper neutralization of special elements used in an SQL Command” (CWE-89).

Version Affected Solution
FortiClientEMS 8.0 Not affected Not Applicable
FortiClientEMS 7.4 7.4.4 Upgrade to 7.4.5 or above
FortiClientEMS 7.2 Not affected Not Applicable

Gwendal Guégniaud from the Fortinet Product Security team discovered the vulnerability, and there is no evidence of it being exploited publicly as of now.

Security teams are advised to review their logs for suspicious HTTP requests targeting the EMS GUI and, where possible, isolate management interfaces from the public internet until the patch can be applied.

Impact of an Unauthenticated Remote Code Execution (RCE) Vulnerability

An unauthenticated Remote Code Execution (RCE) vulnerability is a serious security risk. If exploited, the impact can be severe:

Full System Compromise: Attackers can gain complete control over the compromised FortiClientEMS server.

Data Exfiltration: Sensitive organizational data, including client information, configuration files, and intellectual property, could be stolen.

Malware Deployment: The compromised server can be used as a beachhead to deploy ransomware, cryptominers, or other malicious software throughout the network.

Persistent Access: Attackers can establish backdoors to maintain access even after the initial vulnerability is patched.

Operational Disruption: Critical services managed by FortiClientEMS could be disrupted, leading to downtime and financial losses.

Check Also

F5

F5 Patches NGINX Flaw for Code Execution and DoS Attacks

F5 has shared a security warning about serious flaws in NGINX. These issues could let …