logo

Critical Weaver E-cology RCE Vulnerability Actively Exploited in Attacks

ID: f1bf6d3f-f5a1-5cec-9987-dd26f85b71c5

STIX ID: report--f1bf6d3f-f5a1-5cec-9987-dd26f85b71c5

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Abinaya

...
...

A critical unauthenticated RCE (CVE-2026-22679, CVSS 9.8) in Weaver E-cology was actively exploited shortly after a vendor patch; attackers used the exposed debug endpoint to execute commands, verify access via ping callbacks, and attempt to deliver multiple malicious payloads (executables, MSI, and fileless PowerShell). The report includes IOCs (IP addresses, filenames, a SHA256 hash), host indicators (java.exe spawning shell/network utilities), and mitigation advice to update to build 20260312+, monitor JVM-parented processes, and review traffic to the affected API paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.