logo

Qinglong Vulnerabilities Enable RCE, Exploited in Attacks

ID: e58aaabb-3a36-55be-8949-2d2a4aba9170

STIX ID: report--e58aaabb-3a36-55be-8949-2d2a4aba9170

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Lucas Martin

...
...

Critical authentication-bypass vulnerabilities in the Qinglong self-hosted task scheduler (CVE-2026-3965 and CVE-2026-4047) have been exploited in the wild since early February 2026 to achieve unauthenticated RCE and install a persistent cryptominer dubbed .fullgc; affected instances show 85–100% CPU usage, Alibaba Cloud flagged impacted systems, and maintainers released a patch and mitigation guidance (update Docker image, search for /ql/data/db/.fullgc and config.sh modifications, audit processes, and restrict public exposure).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.