logo

Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild

ID: 8125a7eb-62f6-5224-be0d-800741ddf4c4

STIX ID: report--8125a7eb-62f6-5224-be0d-800741ddf4c4

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Abinaya

...
...

**Executive summary:** In early 2026, attackers actively exploited two authentication-bypass vulnerabilities in the popular Qinglong task scheduler to gain unauthenticated remote code execution and deploy a concealed cryptominer (fullgc), driving CPU usage to 100% on affected Docker and VPS deployments; maintainers patched the flaws and advised operators to update containers, audit for malicious files, and restrict panel access behind VPNs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.