logo

Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

ID: 489e65e0-8a46-5772-9236-39b82ab42a86

STIX ID: report--489e65e0-8a46-5772-9236-39b82ab42a86

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A critical unauthenticated RCE (CVE-2026-22679, CVSS 9.8) in Weaver E-cology 10.0 was actively exploited in March 2026 via the /papi/esearch/data/devops/dubboApi/debug/method endpoint, enabling attackers to run arbitrary commands; observers reported attempted MSI payload drops and PowerShell payload retrievals, and researchers published detection scripts and advised immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.