More than 12,000 internet-exposed instances of open-source AI agent builder Flowise could be compromised by the ongoing exploitation of the maximum-severity code injection flaw, tracked as CVE-2025-59528, which could lead to remote code execution, reports The Hacker News.
BleepingComputer reports that the Cybersecurity and Infrastructure Security Agency has called on federal civilian executive agencies to remediate Fortinet FortiClient Enterprise Management Server instances affected by the actively exploited pre-authentication API access bypass zero-day, tracked as CVE-2026-35616, by midnight of Apr. 9, as it added the flaw to its Known Exploited Vulnerabilities catalog.
Researchers at watchTowr identified an authentication bypass (CVE-2026-2699) and a remote code execution flaw (CVE-2026-2701) within the Storage Zones Controller (SZC) component of Progress ShareFile versions 5.x.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.