logo

Qinglong Task Scheduler RCE Flaws Exploited in the Wild

ID: 9579b0b4-8d12-556c-b872-89fbd22af367

STIX ID: report--9579b0b4-8d12-556c-b872-89fbd22af367

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Divya

...
...

Qinglong versions 2.20.1 and earlier are being actively exploited via two authentication-bypass flaws (CVE-2026-3965 — password reset via URL rewriting, and CVE-2026-4047 — case-insensitive path bypass enabling unauthenticated RCE). Attackers escalate to full control, modify configuration to download a persistent cryptominer saved as a hidden file named .fullgc (targeting Linux and macOS), and cause near-100% CPU usage; project maintainers have released patches and administrators are urged to update containers, search for the .fullgc file and unauthorized external domains, and restrict admin panels behind VPNs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.