Active Exploitation of Weaver E-cology RCE Vulnerability CVE-2026-22679

Active Exploitation of Weaver E-cology RCE Vulnerability CVE-2026-22679

First seen 5 May 2026, 16:37 UTC BleepingcomputerCybersecuritynewsScworld 83% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-22679) in the Weaver E-cology platform is being actively exploited. This unauthenticated remote code execution flaw affects Weaver E-cology 10.0 builds released before March 12, 2026. The vulnerability stems from an exposed debug API endpoint that allows attackers to execute arbitrary commands without authentication. Attacks began in mid-March 2026, shortly after a security update was released, and researchers observed multiple phases of exploitation, including attempts to deploy malicious payloads. Despite the attackers' efforts, endpoint defenses blocked most of their activities, and no persistent sessions were established. Users are urged to apply the latest security updates to mitigate the risk. The CVSS score for this vulnerability is 9.8, indicating its critical nature. The vendor's fix removes the debug endpoint entirely, making immediate updates essential for affected organizations.

Key Points: • CVE-2026-22679 is a critical RCE vulnerability with a CVSS score of 9.8. • Active exploitation began in mid-March 2026, shortly after a security update was released. • Users of Weaver E-cology 10.0 are advised to upgrade to the latest version to mitigate risks.

ThreatCluster AI

Timeline

2026-03-12
Security update released for Weaver E-cology
2026-04-07
CVE-2026-22679 published
2026-04-07
Active exploitation of CVE-2026-22679 reported
2026-04-16
First public PoC for CVE-2026-22679 released
2026-05-04
Bleepingcomputer article published detailing the attacks
2026-05-05
Cybersecuritynews article published on ongoing threats

Community

Browse all →