XWiki is an open-source, Java-based wiki platform used by organizations to host collaborative content and knowledge.
XWiki is an open-source, Java-based wiki platform used by organizations to host collaborative content and knowledge. A recently disclosed vulnerability in XWiki is being actively exploited in the wild by multiple threat actors to compromise servers, build and rent botnets, and enable cryptocurrency mining, with cybersecurity authorities listing it among known exploited vulnerabilities.
The 2026 Verizon Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation has overtaken stolen credentials as the primary entry point for data breaches, accounting for 31% of incidents. This…
The RondoDox botnet is exploiting the unpatched XWiki remote code execution vulnerability CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, many servers remain vulnerable,…
The RondoDox botnet is exploiting the unpatched XWiki remote code execution (RCE) flaw CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, the botnet continues to infect servers,…
A vulnerability in XWiki software is being actively exploited by various threat actors, including botnets and coin-miners. VulnCheck reported on November 14, 2025, that these actors are using a range of tools to target…
Hackers are actively exploiting a critical vulnerability in XWiki, tracked as CVE-2025-24893, to hire servers for botnet operations. This exploitation has escalated from isolated incidents to widespread attacks…
A vulnerability in XWiki software is being actively exploited by various threat actors, including botnets and coin-miners. VulnCheck reported on November 14, 2025, that these actors are utilizing a range of tools, from…
Hackers are actively exploiting a critical vulnerability in XWiki, tracked as CVE-2025-24893, to hire servers for botnet operations. This exploitation has transitioned from isolated incidents to widespread attacks…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities related to the XWiki Platform and Broadcom's VMware Aria Operations and VMware Tools to its Known Exploited Vulnerabilities…
VulnCheck has launched Canary Intelligence, a tool that provides verified evidence of active exploitation from live, intentionally vulnerable systems. This product aims to assist security teams in confirming which…
Hackers have exploited a critical vulnerability in XWiki, identified as CVE-2025-24893, to hijack corporate servers for cryptocurrency mining. Active attacks have been confirmed by VulnCheck researchers, with exploits…