Attackers exploit critical Flowise flaw CVE-2025-59528 for remote code execution

2026-04-08T02:51:46Zd3ca062794bb7247b2a1a42158a1ecab013c2efb53d4e47a8f80d56043fdfb8f
BlueHammerCISA KEVCVE-2025-53521CVE-2025-59528CVE-2026-35616DPRK phishingF5 BIG-IP APMFlowiseFortinet FortiClient EMSGPU RowHammerGPUBreachGitHub C2MedusaREvilRussian banking outageStorm-1175active exploitationlaw enforcement takedownnation-stateprivilege escalationransomwareremote code executionservice outagevulnerabilityzero-day

What happened

Multiple high-impact vulnerabilities and active exploitation campaigns were reported: attackers are actively exploiting a critical Flowise RCE (CVE-2025-59528, CVSS 10) enabling remote code execution and filesystem access; over 14,000 F5 BIG-IP APM instances remain exposed and are being targeted via CVE-2025-53521 (CVSS 9.8); Fortinet patched an actively exploited FortiClient EMS flaw (CVE-2026-35616, CVSS 9.1) which CISA added to its Known Exploited Vulnerabilities catalog. Additional notable threats include publication of an unpatched Windows privilege-escalation zero-day (“BlueHammer”), new

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d3ca062794bb7247b2a1a42158a1ecab013c2efb53d4e47a8f80d56043fdfb8f
Enrichment time
2026-04-08T02:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.