Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
2026-04-07T07:24:23Z•408f047ee0129ae9a436e538db26555d60da5ad8fa23e6fcd3d507f98d6f9931
BYOVDactive-exploitationciscocode-injectioncredential-harvestcritical-vulnerabilitydprkflowisefortinetgit-hub-c2iran-linkednextjsnpm-malwarepassword-sprayingransomwarercereact2shellsocial-engineeringsupply-chainweb-shell
What happened
Multiple high-impact incidents and actively exploited critical flaws were reported. Most notably, Flowise (open-source AI) is under active exploitation for a code-injection RCE (CVE-2025-59528, CVSS 10.0) with 12,000+ exposed instances. Other high-severity, actively exploited or patched vulnerabilities include Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.1) and Cisco IMC/SSM (CVE-2026-20093, CVSS 9.8). Large-scale credential theft operations are exploiting the React2Shell/Next.js flaw (CVE-2025-55182). The feed also highlights serious supply-chain and social-engineering incidents (Axios/UN
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 408f047ee0129ae9a436e538db26555d60da5ad8fa23e6fcd3d507f98d6f9931
- Enrichment time
- 2026-04-07T07:24:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.