Qinglong Task Scheduler RCE Flaws Exploited in the Wild
ID: 9579b0b4-8d12-556c-b872-89fbd22af367
STIX ID: report--9579b0b4-8d12-556c-b872-89fbd22af367
Feed Name: GBHackers
Qinglong versions 2.20.1 and earlier are being actively exploited via two authentication-bypass flaws (CVE-2026-3965 — password reset via URL rewriting, and CVE-2026-4047 — case-insensitive path bypass enabling unauthenticated RCE). Attackers escalate to full control, modify configuration to download a persistent cryptominer saved as a hidden file named .fullgc (targeting Linux and macOS), and cause near-100% CPU usage; project maintainers have released patches and administrators are urged to update containers, search for the .fullgc file and unauthorized external domains, and restrict admin panels behind VPNs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
