Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild
ID: 8125a7eb-62f6-5224-be0d-800741ddf4c4
STIX ID: report--8125a7eb-62f6-5224-be0d-800741ddf4c4
Feed Name: cybersecurityNews.com
Threat Score
**Executive summary:** In early 2026, attackers actively exploited two authentication-bypass vulnerabilities in the popular Qinglong task scheduler to gain unauthenticated remote code execution and deploy a concealed cryptominer (fullgc), driving CPU usage to 100% on affected Docker and VPS deployments; maintainers patched the flaws and advised operators to update containers, audit for malicious files, and restrict panel access behind VPNs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
