CVE-2025-24893 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
October 29, 2025
Last Seen
March 9, 2026

CVE-2025-24893 is a vulnerability tracked across 11 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed October 29, 2025; most recent activity March 9, 2026.

Related Threat Clusters

  • RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Vulnerability

    The RondoDox botnet is exploiting the unpatched XWiki remote code execution vulnerability CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, many servers remain vulnerable,…

    3 articles · Updated November 17, 2025
  • Cloud Attacks Shift Focus to Exploiting Software Vulnerabilities

    Hackers are increasingly targeting newly disclosed vulnerabilities in third-party software to access cloud environments, with the time frame for such attacks decreasing significantly. Google reports a notable decline in…

    1 article · Updated March 9, 2026
  • RondoDox Botnet Exploits React2Shell Flaw in Next.js Servers

    The RondoDox botnet has been exploiting the React2Shell flaw (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. First documented by Fortinet in July 2025, the botnet targets multiple n-day…

    1 article · Updated December 31, 2025
  • RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Flaw

    The RondoDox botnet is exploiting the unpatched XWiki remote code execution (RCE) flaw CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, the botnet continues to infect servers,…

    5 articles · Updated November 17, 2025
  • Multiple Threat Actors Exploit XWiki Vulnerability

    A vulnerability in XWiki software is being actively exploited by various threat actors, including botnets and coin-miners. VulnCheck reported on November 14, 2025, that these actors are using a range of tools to target…

    2 articles · Updated November 17, 2025
  • Widespread Exploitation of XWiki Vulnerability for Botnet Recruitment

    Hackers are actively exploiting a critical vulnerability in XWiki, tracked as CVE-2025-24893, to hire servers for botnet operations. This exploitation has escalated from isolated incidents to widespread attacks…

    3 articles · Updated November 17, 2025
  • XWiki Vulnerability Targeted by Multiple Threat Actors

    A vulnerability in XWiki software is being actively exploited by various threat actors, including botnets and coin-miners. VulnCheck reported on November 14, 2025, that these actors are utilizing a range of tools, from…

    2 articles · Updated November 17, 2025
  • Exploitation of XWiki Vulnerability Leads to Botnet Creation

    Hackers are actively exploiting a critical vulnerability in XWiki, tracked as CVE-2025-24893, to hire servers for botnet operations. This exploitation has transitioned from isolated incidents to widespread attacks…

    3 articles · Updated November 17, 2025
  • VulnCheck Launches Canary Intelligence for Real-Time Exploitation Data

    VulnCheck has launched Canary Intelligence, a tool that provides verified evidence of active exploitation from live, intentionally vulnerable systems. This product aims to assist security teams in confirming which…

    2 articles · Updated November 17, 2025
  • Hackers Exploit XWiki Vulnerability for Cryptocurrency Mining

    Hackers have exploited a critical vulnerability in XWiki, identified as CVE-2025-24893, to hijack corporate servers for cryptocurrency mining. Active attacks have been confirmed by VulnCheck researchers, with exploits…

    2 articles · Updated October 29, 2025

Recent Intelligence Reports

  • Google: Cloud attacks exploit flaws more than weak credentials — Bleepingcomputer · March 9, 2026
  • RondoDox botnet exploits React2Shell flaw to breach Next.js servers — Bleepingcomputer · December 31, 2025
  • RondoDox botnet malware now hacks servers using XWiki flaw — Bleepingcomputer · November 17, 2025
  • XWiki bug actively exploited by multiple threat actors — Scworld · November 17, 2025
  • XWiki bug actively exploited by multiple threat actors — Scmagazine · November 17, 2025
  • VulnCheck Launches Canary Intelligence to Provide Verified Evidence of Active Exploitation — Morningstar · November 17, 2025
  • RondoDox expands botnet by exploiting XWiki RCE bug left unpatched since February 2025 — Securityaffairs.Co · November 17, 2025
  • Hackers Hiring Servers for Botnet by Exploiting XWiki Vulnerability in the Wild — Cyberpress · November 17, 2025

CVSS v3.1 Breakdown