XWiki — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
October 29, 2025
Last Seen
May 20, 2026

XWiki is an open-source, Java-based wiki platform used by organizations to host collaborative content and knowledge.

Overview

XWiki is an open-source, Java-based wiki platform used by organizations to host collaborative content and knowledge. A recently disclosed vulnerability in XWiki is being actively exploited in the wild by multiple threat actors to compromise servers, build and rent botnets, and enable cryptocurrency mining, with cybersecurity authorities listing it among known exploited vulnerabilities.

Related Threat Clusters

  • Vulnerability Exploitation Surpasses Credential Theft as Leading Cyber Breach Vector

    The 2026 Verizon Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation has overtaken stolen credentials as the primary entry point for data breaches, accounting for 31% of incidents. This…

    33 articles · Updated May 20, 2026
  • RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Vulnerability

    The RondoDox botnet is exploiting the unpatched XWiki remote code execution vulnerability CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, many servers remain vulnerable,…

    3 articles · Updated November 17, 2025
  • RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Flaw

    The RondoDox botnet is exploiting the unpatched XWiki remote code execution (RCE) flaw CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, the botnet continues to infect servers,…

    5 articles · Updated November 17, 2025
  • Multiple Threat Actors Exploit XWiki Vulnerability

    A vulnerability in XWiki software is being actively exploited by various threat actors, including botnets and coin-miners. VulnCheck reported on November 14, 2025, that these actors are using a range of tools to target…

    2 articles · Updated November 17, 2025
  • Widespread Exploitation of XWiki Vulnerability for Botnet Recruitment

    Hackers are actively exploiting a critical vulnerability in XWiki, tracked as CVE-2025-24893, to hire servers for botnet operations. This exploitation has escalated from isolated incidents to widespread attacks…

    3 articles · Updated November 17, 2025
  • XWiki Vulnerability Targeted by Multiple Threat Actors

    A vulnerability in XWiki software is being actively exploited by various threat actors, including botnets and coin-miners. VulnCheck reported on November 14, 2025, that these actors are utilizing a range of tools, from…

    2 articles · Updated November 17, 2025
  • Exploitation of XWiki Vulnerability Leads to Botnet Creation

    Hackers are actively exploiting a critical vulnerability in XWiki, tracked as CVE-2025-24893, to hire servers for botnet operations. This exploitation has transitioned from isolated incidents to widespread attacks…

    3 articles · Updated November 17, 2025
  • CISA Adds XWiki and VMware Vulnerabilities to KEV Catalog

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities related to the XWiki Platform and Broadcom's VMware Aria Operations and VMware Tools to its Known Exploited Vulnerabilities…

    2 articles · Updated October 31, 2025
  • VulnCheck Launches Canary Intelligence for Real-Time Exploitation Data

    VulnCheck has launched Canary Intelligence, a tool that provides verified evidence of active exploitation from live, intentionally vulnerable systems. This product aims to assist security teams in confirming which…

    2 articles · Updated November 17, 2025
  • Hackers Exploit XWiki Vulnerability for Cryptocurrency Mining

    Hackers have exploited a critical vulnerability in XWiki, identified as CVE-2025-24893, to hijack corporate servers for cryptocurrency mining. Active attacks have been confirmed by VulnCheck researchers, with exploits…

    2 articles · Updated October 29, 2025

Recent Intelligence Reports

  • Vulnerability Exploitation Trends: Exploits Overtake Credentials — Aicerts.Ai · May 20, 2026
  • XWiki bug actively exploited by multiple threat actors — Scworld · November 17, 2025
  • XWiki bug actively exploited by multiple threat actors — Scmagazine · November 17, 2025
  • VulnCheck Launches Canary Intelligence to Provide Verified Evidence of Active Exploitation — Morningstar · November 17, 2025
  • Hackers Weaponize XWiki Flaw to Build and Rent Out Botnet Networks — Gbhackers · November 17, 2025
  • Hackers Hiring Servers for Botnet by Exploiting XWiki Vulnerability in the Wild — Cyberpress · November 17, 2025
  • RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet — Thehackernews · November 15, 2025
  • CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog — Feeds.Feedburner · October 31, 2025

CVSS v3.1 Breakdown