Critical ShowDoc RCE Vulnerability Exploited in the Wild
ID: 4fa9445e-c63a-5799-ba86-e05fbe58e66d
STIX ID: report--4fa9445e-c63a-5799-ba86-e05fbe58e66d
Feed Name: ThreatCluster
Threat Score
### Executive Summary A critical remote code execution vulnerability (CVE-2025-0520, CVSS 9.4) in ShowDoc is being actively exploited in the wild against instances running versions prior to 2.8.7; ShowDoc has since released newer versions (latest noted 3.8.1) but many deployments remain unpatched. Exploits were observed against a U.S.-based honeypot, highlighting active attacks beyond predominantly Chinese-hosted instances and prompting urgent mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
