Attackers exploit critical Flowise flaw CVE-2025-59528 for remote code execution
2026-04-08T02:51:46Z•d3ca062794bb7247b2a1a42158a1ecab013c2efb53d4e47a8f80d56043fdfb8f
BlueHammerCISA KEVCVE-2025-53521CVE-2025-59528CVE-2026-35616DPRK phishingF5 BIG-IP APMFlowiseFortinet FortiClient EMSGPU RowHammerGPUBreachGitHub C2MedusaREvilRussian banking outageStorm-1175active exploitationlaw enforcement takedownnation-stateprivilege escalationransomwareremote code executionservice outagevulnerabilityzero-day
What happened
Multiple high-impact vulnerabilities and active exploitation campaigns were reported: attackers are actively exploiting a critical Flowise RCE (CVE-2025-59528, CVSS 10) enabling remote code execution and filesystem access; over 14,000 F5 BIG-IP APM instances remain exposed and are being targeted via CVE-2025-53521 (CVSS 9.8); Fortinet patched an actively exploited FortiClient EMS flaw (CVE-2026-35616, CVSS 9.1) which CISA added to its Known Exploited Vulnerabilities catalog. Additional notable threats include publication of an unpatched Windows privilege-escalation zero-day (“BlueHammer”), new
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d3ca062794bb7247b2a1a42158a1ecab013c2efb53d4e47a8f80d56043fdfb8f
- Enrichment time
- 2026-04-08T02:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.