logo

Critical ShowDoc RCE Vulnerability Actively Exploited in the Wild

ID: 346156d9-5c70-57b7-a60b-df6f1ec14c5a

STIX ID: report--346156d9-5c70-57b7-a60b-df6f1ec14c5a

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: AnuPriya

...
...

Researchers warn of an actively exploited unauthenticated RCE (CNVD-2020-26585) in ShowDoc versions before 2.8.7 that permits attackers to upload PHP webshells via the /index.php?s=/home/page/uploadImg endpoint, enabling full remote code execution; administrators are urged to upgrade to 2.8.7+, restrict external access, deploy WAFs, and monitor logs for malicious uploads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.