RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Flaw

RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Flaw

First seen 2 Dec 2025, 18:33 UTC RedditThehackernewsSecurityaffairs.CoBleepingcomputer 72% similarity 59.2

Article Content

Browse articles
ThreatCluster

The RondoDox botnet is exploiting the unpatched XWiki remote code execution (RCE) flaw CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, the botnet continues to infect servers, significantly expanding its capabilities and targeting enterprise systems. Recent reports indicate a 650% increase in exploit vectors, with attacks being carried out by multiple threat actors.

ThreatCluster AI

Community

Browse all →