Skip to content
RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Vulnerability

RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Vulnerability

First seen 17 Nov 2025, 09:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The RondoDox botnet is exploiting the unpatched XWiki remote code execution vulnerability CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, many servers remain vulnerable, allowing RondoDox to infect additional devices and expand its network. The attack targets unpatched XWiki servers, increasing the botnet's reach.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track RondoDox and CVE-2025-24893 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed