logo

Critical Weaver E-cology RCE Exploit Raises Alarm for Enterprise Systems

ID: dd02eebd-7087-564f-ae0a-6c0e2bf0d92f

STIX ID: report--dd02eebd-7087-564f-ae0a-6c0e2bf0d92f

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Divya

...
...

A critical unauthenticated RCE (CVE-2026-22679, CVSS 9.8) in Weaver E-cology 10.0 (pre-20260312) was actively exploited in the wild from mid-March 2026 through an exposed debug endpoint that forwards attacker-controlled parameters into the Dubbo RPC invoker; attackers achieved OS-level command execution via the application's JVM and conducted a multi-stage campaign (verification via ping callbacks, attempted payload downloads, an MSI delivery, and fileless PowerShell retrieval), leaving multiple IOCs (IPs, URLs, and an MSI SHA256).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.