Close Menu
    What's Hot

    Homeowners are suddenly pulling their houses off the market—and this is why

    With His New Museum, Obama Offers a Trip to a Parallel America

    Opinion | The Strait of Hormuz Is Blocked. The World Is Adjusting.

    Facebook X (Twitter) Instagram
    Trending
    • Homeowners are suddenly pulling their houses off the market—and this is why
    • With His New Museum, Obama Offers a Trip to a Parallel America
    • Opinion | The Strait of Hormuz Is Blocked. The World Is Adjusting.
    • The Iran War Is Decarbonizing the Global South
    • These two founders left Goldman and Meta to build voice AI for markets everyone else overlooked
    • Datadog, Inc. (DDOG) Presents at Bank of America 2026 Global Technology Conference Transcript
    • USWNT’s Trinity Rodman on Triple Espresso: ‘Having my sisters back is amazing’
    • Amazon will show AI product images when you search for some reason
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

    adminBy adminMay 5, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMay 05, 2026Vulnerability / Network Security

    Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

    A critical security vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation (OA) and collaboration platform, has come under active exploitation in the wild.

    The vulnerability (CVE-2026-22679, CVSS score: 9.8) relates to a case of unauthenticated remote code execution affecting Weaver E-cology 10.0 versions prior to 20260312. The issue resides in the “/papi/esearch/data/devops/dubboApi/debug/method” endpoint that allows an attacker to execute arbitrary commands by invoking exposed debug functionality.

    “Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system,” according to a description of the flaw in the NIST National Vulnerability Database (NVD).

    The advisory also noted that the Shadowserver Foundation observed the first signs of active exploitation on March 31, 2026. Chinese security vendor QiAnXin said it was able to successfully reproduce the remote code execution vulnerability in its own alert released on March 17, 2026.

    Cybersecurity

    However, in a report published last week, the Vega Research Team said it identified active exploitation of CVE-2026-22679, with the earliest evidence of abuse dating back to March 17, 2026, five days after patches were shipped for the flaw.

    “The intrusion unfolded over roughly a week of operator activity: RCE verification, three failed payload drops, an attempted pivot to an MSI implant that did not produce a working install, and a short burst of attempts to retrieve PowerShell payloads from attacker-controlled infrastructure,” security researcher Daniel Messing said.

    The MSI installer, per the Israeli cybersecurity company, used the name “fanwei0324.msi,” indicating an attempt to pass off the malicious payload as harmless by using the romanized Chinese name for Weaver. The unknown threat actor has also been observed running discovery commands, such as whoami, ipconfig, and tasklist, throughout the campaign.

    Security researcher Kerem Oruc has made available a Python-based detection script that identifies vulnerable Weaver E-cology instances by checking if the susceptible API endpoint is accessible. Users are advised to apply the updates, if not already, to stay protected.

    Actively API CVE202622679 Debug ecology Exploited flaw RCE Weaver
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleCeasefire teetering as Trump threatens Iran will be ‘blown off the face of the earth’
    Next Article Mini Motorways Is Letting Players Vote For Its Next City Map
    admin
    • Website

    Related Posts

    Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

    June 4, 2026

    Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

    June 4, 2026

    Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT

    June 3, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Homeowners are suddenly pulling their houses off the market—and this is why

    With His New Museum, Obama Offers a Trip to a Parallel America

    Opinion | The Strait of Hormuz Is Blocked. The World Is Adjusting.

    The Iran War Is Decarbonizing the Global South

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by