Fortinet BIG-IP Vulnerability Reclassified as RCE, Under Exploitation
ID: a3d042bf-854c-5fc6-876f-e9a6924337b9
STIX ID: report--a3d042bf-854c-5fc6-876f-e9a6924337b9
Feed Name: Dark Reading
Fortinet's BIG-IP vulnerability CVE-2025-53521 was reclassified from a DoS to a critical RCE (CVSS 9.8) and is being actively exploited in the wild; Fortinet published IoCs (including files like /run/bigtlog.pipe and mismatched /usr/bin/umount hashes) and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Additionally, scanning/exploitation activity has been observed against FortiClient EMS (CVE-2026-21643, a critical SQL injection), and customers are urged to patch and hunt for indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
