Critical Weaver E-cology RCE Exploit Raises Alarm for Enterprise Systems
ID: dd02eebd-7087-564f-ae0a-6c0e2bf0d92f
STIX ID: report--dd02eebd-7087-564f-ae0a-6c0e2bf0d92f
Feed Name: GBHackers
A critical unauthenticated RCE (CVE-2026-22679, CVSS 9.8) in Weaver E-cology 10.0 (pre-20260312) was actively exploited in the wild from mid-March 2026 through an exposed debug endpoint that forwards attacker-controlled parameters into the Dubbo RPC invoker; attackers achieved OS-level command execution via the application's JVM and conducted a multi-stage campaign (verification via ping callbacks, attempted payload downloads, an MSI delivery, and fileless PowerShell retrieval), leaving multiple IOCs (IPs, URLs, and an MSI SHA256).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
