Safeguard
Vulnerability Analysis

FortiClient EMS and FortiWeb Add Five More Confirmed-Exploited CVEs to Fortinet's Year

A SQL injection and an access-control bug in FortiClient EMS, a path traversal and command injection pair in FortiWeb — Fortinet's endpoint management and WAF products join the list.

Safeguard Research Team
4 min read

Fortinet had five more vulnerabilities confirmed exploited over the past year beyond the FortiOS and FortiSandbox findings already covered in this series — this time concentrated in FortiClient EMS, FortiWeb, and a multi-product authentication bypass.

CVECVSSProductMechanism
CVE-2026-216439.8FortiClient EMSSQL injection
CVE-2026-356169.8FortiClient EMSImproper access control
CVE-2026-248589.8Multiple (FortiAnalyzer and others)Authentication bypass via alternate path
CVE-2025-644469.8FortiWebRelative path traversal
CVE-2025-580347.2FortiWebOS command injection

Why FortiClient EMS getting two critical CVEs matters beyond the endpoint

FortiClient EMS (Endpoint Management Server) is the centralized console managing FortiClient deployment and policy across an organization's endpoint fleet — the same management-plane risk pattern recurring throughout this series. Two critical vulnerabilities against it, one a SQL injection and one an access-control failure, both scoring 9.8, describe two independent paths to compromising the console with authority over every endpoint it manages, which is a materially more consequential finding than an equivalent bug in any single managed endpoint.

Why FortiWeb's pairing deserves attention as a pattern

FortiWeb, Fortinet's web application firewall product, had a relative path traversal bug and a separate OS command injection vulnerability confirmed exploited within days of each other in November 2025 — another instance of the pattern seen with SonicWall and Cisco earlier in this series, where two related findings in close succession against the same product suggest a concentrated security review or a single exploitation campaign working through more than one weakness at once. There's a specific irony worth naming here too, echoing the FortiSandbox finding covered earlier: a web application firewall exists specifically to filter malicious requests before they reach the applications behind it, and having its own path traversal and command injection vulnerabilities means the filter itself became a target rather than remaining purely a defensive layer.

What to check this week

Patch FortiClient EMS with priority given the two critical, unauthenticated-adjacent findings against its management console specifically — a compromised EMS instance potentially affects policy and configuration across the entire managed endpoint fleet.

Review FortiWeb's deployment position carefully, given that a compromised WAF sits directly in front of whatever application it's meant to protect. A path traversal or command injection bug in the WAF itself can potentially bypass the very protection the application behind it was relying on.

Confirm which specific products are affected by CVE-2026-24858's authentication bypass, since Fortinet's advisory names it as affecting multiple products — a broader remediation scope than a single-product finding would require.

Why treating Fortinet as a single risk surface understates the picture

Between the FortiOS, FortiSandbox, FortiClient EMS, and FortiWeb findings now covered across this series, Fortinet's product portfolio has produced confirmed-exploited vulnerabilities across essentially every major category of its business — network operating system, malware sandboxing, endpoint management, and web application firewalling. An organization running several Fortinet products should track each one's advisory history independently rather than assuming a clean bill of health for one product says anything about the others.

A closing note on multi-product Fortinet estates

Organizations running several Fortinet products in the same environment — a common pattern given the vendor's broad security portfolio — should specifically verify that a security review of one product hasn't been mistaken for coverage of the whole estate; each product line's patch history in this series has been independent.

A final consideration on WAF trust assumptions

Applications sitting behind a web application firewall are frequently built with less input validation of their own, on the reasoning that the WAF already filters malicious traffic upstream — an assumption this cluster directly undermines, and a reason to verify that applications behind FortiWeb still enforce their own input validation independently rather than depending entirely on the firewall in front of them.

How Safeguard helps

Safeguard's continuous inventory tracks security infrastructure — endpoint management consoles, web application firewalls — as first-class assets deserving the same scrutiny as the systems they protect, recognizing the recurring pattern this series has documented across multiple vendors: security products are not exempt from the vulnerability classes they exist to defend against.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.