ProjectDiscovery contributors proposed two changes to the nuclei-templates repository: a new detection template for CVE-2026-21643 in FortiClient EMS 7.4.4 and an update to the existing OpenClaw exposure template after the service was renamed in newer deployments. The FortiClient EMS template targets a pre-authentication SQL injection flaw and uses the unauthenticated /api/v1/init_consts endpoint with an error-based PostgreSQL cast payload designed to elicit a reflected HTTP 500 response. The submitter said the check was validated against both vulnerable and patched systems to confirm accurate detection while avoiding the /api/v1/auth/signin path, which can trigger brute-force lockout after three attempts.
The OpenClaw update replaces a narrower hex request with a more generic mDNS/DNS-SD query so the template can identify both legacy clawdbot and newer openclaw responses, with the contributor reporting successful tests against roughly 20 hosts found via Shodan. ProjectDiscovery’s automated Neo review did not flag security issues in the change, but warned that the broader query and less specific matchers could increase noise and false positives; it recommended considering separate targeted queries for old and new service names, documenting false-positive rates, and correcting an outdated template comment.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A pull request proposed a new Nuclei template to detect CVE-2026-21643, a pre-authentication SQL injection vulnerability affecting FortiClient EMS 7.4.4. The author said the template was validated against vulnerable and patched targets and uses the unauthenticated /api/v1/init_consts endpoint with an error-based PostgreSQL cast payload to avoid brute-force lockout on the signin endpoint.
A pull request proposed updating the Nuclei OpenClaw exposure detection template to use a more generic mDNS/DNS-SD query and match both legacy clawdbot and newer openclaw responses after a service rename. The contributor reported testing the revised detection against about 20 hosts identified via Shodan.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.