Fortinet Issues Emergency Patch for FortiClient Zero-Day
2026-04-06T20:51:50Z•2c287eb0d7990a7baabf51cbdcd49b29521fcd1b2935ad427a3eff559f23afef
ai-malwareaxiosbig-ipcloud-securitycredential-harvestingcve-2025-53521cve-2026-35616deeploadf5forticlientfortinetgenaiin-the-wildnpmrcereact2shellsupply-chainteampcpzero-day
What happened
DarkReading roundup: Fortinet released an emergency patch for a FortiClient authentication-bypass zero-day (CVE-2026-35616) that has been exploited in the wild. The feed also highlights an F5 BIG‑IP vulnerability reclassified as an RCE and under exploitation (CVE-2025-53521), an automated credential‑harvesting campaign abusing React2Shell in exposed Next.js apps, an Axios NPM package compromise, AI-driven malware (DeepLoad), supply‑chain and GenAI security concerns, and escalating cloud/SaaS account takeover activity tied to groups like TeamPCP.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 2c287eb0d7990a7baabf51cbdcd49b29521fcd1b2935ad427a3eff559f23afef
- Enrichment time
- 2026-04-06T20:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.