Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed

2026-04-07T07:24:23Z408f047ee0129ae9a436e538db26555d60da5ad8fa23e6fcd3d507f98d6f9931
BYOVDactive-exploitationciscocode-injectioncredential-harvestcritical-vulnerabilitydprkflowisefortinetgit-hub-c2iran-linkednextjsnpm-malwarepassword-sprayingransomwarercereact2shellsocial-engineeringsupply-chainweb-shell

What happened

Multiple high-impact incidents and actively exploited critical flaws were reported. Most notably, Flowise (open-source AI) is under active exploitation for a code-injection RCE (CVE-2025-59528, CVSS 10.0) with 12,000+ exposed instances. Other high-severity, actively exploited or patched vulnerabilities include Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.1) and Cisco IMC/SSM (CVE-2026-20093, CVSS 9.8). Large-scale credential theft operations are exploiting the React2Shell/Next.js flaw (CVE-2025-55182). The feed also highlights serious supply-chain and social-engineering incidents (Axios/UN

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
408f047ee0129ae9a436e538db26555d60da5ad8fa23e6fcd3d507f98d6f9931
Enrichment time
2026-04-07T07:24:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed · Baitaphish