Fortinet Issues Emergency Patch for FortiClient Zero-Day

2026-04-06T20:51:50Z2c287eb0d7990a7baabf51cbdcd49b29521fcd1b2935ad427a3eff559f23afef
ai-malwareaxiosbig-ipcloud-securitycredential-harvestingcve-2025-53521cve-2026-35616deeploadf5forticlientfortinetgenaiin-the-wildnpmrcereact2shellsupply-chainteampcpzero-day

What happened

DarkReading roundup: Fortinet released an emergency patch for a FortiClient authentication-bypass zero-day (CVE-2026-35616) that has been exploited in the wild. The feed also highlights an F5 BIG‑IP vulnerability reclassified as an RCE and under exploitation (CVE-2025-53521), an automated credential‑harvesting campaign abusing React2Shell in exposed Next.js apps, an Axios NPM package compromise, AI-driven malware (DeepLoad), supply‑chain and GenAI security concerns, and escalating cloud/SaaS account takeover activity tied to groups like TeamPCP.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
2c287eb0d7990a7baabf51cbdcd49b29521fcd1b2935ad427a3eff559f23afef
Enrichment time
2026-04-06T20:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fortinet Issues Emergency Patch for FortiClient Zero-Day · Baitaphish