Product of Fortinet

FortiClient EMS

As of , 3 Fortinet FortiClient EMS vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2023-48788.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2023-48788SQL InjectionFortinet FortiClient EMSPatch this weekRansomware use; Metasploit module; EPSS 0.980.98
2CVE-2026-21643SQL InjectionFortinet FortiClient EMSPatch this weekEPSS 0.940.94
3CVE-2026-35616Improper Access ControlFortinet FortiClient EMSPatch soon0.09

Added each year

0.511.522024: 1120242025: nonenone20252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20241
2025none
20262

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-21643 Fortinet FortiClient EMSEdited: name.

Every change we recorded