logo

Weaver E-cology critical bug exploited in attacks since March

ID: 42b5e439-8310-513b-944f-ab21d28b5614

STIX ID: report--42b5e439-8310-513b-944f-ab21d28b5614

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Bill Toulas

...
...

Researchers observed active exploitation of CVE-2026-22679 — a critical unauthenticated RCE in Weaver E-cology 10.0 — beginning five days after the vendor released a patch; attackers used an exposed debug RPC endpoint to execute system commands, performed reconnaissance (whoami, ipconfig, tasklist), attempted PowerShell-based payload delivery and a targeted MSI installer, but failed to establish persistence and many payloads were blocked. The vendor removed the debug endpoint in build 20260312 and users are advised to apply the security update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.