logo

Fortinet BIG-IP Vulnerability Reclassified as RCE, Under Exploitation

ID: a3d042bf-854c-5fc6-876f-e9a6924337b9

STIX ID: report--a3d042bf-854c-5fc6-876f-e9a6924337b9

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Rob Wright

...
...

Fortinet's BIG-IP vulnerability CVE-2025-53521 was reclassified from a DoS to a critical RCE (CVSS 9.8) and is being actively exploited in the wild; Fortinet published IoCs (including files like /run/bigtlog.pipe and mismatched /usr/bin/umount hashes) and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Additionally, scanning/exploitation activity has been observed against FortiClient EMS (CVE-2026-21643, a critical SQL injection), and customers are urged to patch and hunt for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.