snyk.io Qinglong Task Scheduler Vulnerabilities Exploited for Cryptomining Attacks
Article Content
- •Two critical vulnerabilities in Qinglong allow unauthenticated remote code execution.
- •Attackers deployed a cryptominer named .fullgc, causing significant CPU resource drain.
- •Initial mitigations were ineffective, leading to further exploitation before a proper fix was issued.
In early February 2026, hackers exploited two critical authentication bypass vulnerabilities in the Qinglong task scheduling platform, affecting versions 2.20.1 and earlier. These vulnerabilities, identified as CVE-2026-3965 and CVE-2026-4047, allowed unauthenticated remote code execution, enabling attackers to deploy a cryptominer binary named .fullgc on compromised servers. The attacks were first reported by users experiencing high CPU usage due to the hidden process, which mimicked a legitimate system process to evade detection. The vulnerabilities stemmed from a mismatch between the security middleware's assumptions and the Express.js routing behavior. Despite the initial reports, the Qinglong maintainers only acknowledged the issue on March 1, 2026, urging users to update their systems. However, the initial mitigation was insufficient, and a more effective fix was implemented later. The exploitation has been confirmed across various setups, including those behind Nginx and SSL. The situation highlights the risks associated with publicly exposed application panels.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-3965 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…