Critical Zero-Day: Unauthenticated RCE Exploited in Weaver E-cology 10.0
ID: 4ca1db87-631a-535e-83b8-5627b06487a8
STIX ID: report--4ca1db87-631a-535e-83b8-5627b06487a8
Feed Name: securityonline.info
Threat Score
**CVE-2026-22679** — A critical unauthenticated RCE in Weaver (Fanwei) E-cology 10.0 via the /papi/esearch/data/devops/dubboApi/debug/method debug endpoint (CVSS 9.3). Shadowserver reported active exploitation on 2026-03-31; vendor patches were released on 2026-03-12. Organizations are advised to patch immediately, restrict access to the /papi/ directory if patching is delayed, and hunt webserver logs for suspicious POST requests targeting the exposed endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
