Qinglong Vulnerabilities Enable RCE, Exploited in Attacks
ID: e58aaabb-3a36-55be-8949-2d2a4aba9170
STIX ID: report--e58aaabb-3a36-55be-8949-2d2a4aba9170
Feed Name: Cyber Press
Critical authentication-bypass vulnerabilities in the Qinglong self-hosted task scheduler (CVE-2026-3965 and CVE-2026-4047) have been exploited in the wild since early February 2026 to achieve unauthenticated RCE and install a persistent cryptominer dubbed .fullgc; affected instances show 85–100% CPU usage, Alibaba Cloud flagged impacted systems, and maintainers released a patch and mitigation guidance (update Docker image, search for /ql/data/db/.fullgc and config.sh modifications, audit processes, and restrict public exposure).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
