logo

Critical Weaver E-cology RCE Flaw Actively Exploited by Attackers

ID: adc50330-f8fd-5394-a49b-152a2be9420c

STIX ID: report--adc50330-f8fd-5394-a49b-152a2be9420c

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: AnuPriya

...
...

A critical unauthenticated RCE (CVE-2026-22679, CVSS 9.8) in Weaver E-cology allowed attackers to invoke Dubbo RPC methods via a public debug endpoint, leading to JVM-based command execution; the vendor removed the endpoint in build 20260312, but active exploitation began in mid-March 2026, with payload hosting, PowerShell download-and-execute attempts, an MSI artifact, and several IP/URL/hash IoCs listed — organizations should patch immediately, restrict OA internet exposure, monitor java.exe child processes and EDR logs, and block the reported infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.