More than 12,000 internet-exposed instances of open-source AI agent builder Flowise could be compromised by the ongoing exploitation of the maximum-severity code injection flaw, tracked as CVE-2025-59528, which could lead to remote code execution, reports The Hacker News.
BleepingComputer reports that the Cybersecurity and Infrastructure Security Agency has called on federal civilian executive agencies to remediate Fortinet FortiClient Enterprise Management Server instances affected by the actively exploited pre-authentication API access bypass zero-day, tracked as CVE-2026-35616, by midnight of Apr. 9, as it added the flaw to its Known Exploited Vulnerabilities catalog.