Close Menu
    What's Hot

    Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

    An OpenAI model went rogue on the internet and stole test answers 

    Trump Prepares Yet Another Strategy to Resurrect Global Tariffs

    Facebook X (Twitter) Instagram
    Trending
    • Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
    • An OpenAI model went rogue on the internet and stole test answers 
    • Trump Prepares Yet Another Strategy to Resurrect Global Tariffs
    • The Best Vacuum for Pet Hair—We Tested Many to Find Which Ones Work Best (2026)
    • Edward O’Keefe Named C.E.O. of WNET
    • Even as War Rages, Investors Bet Oil Will Be Cheaper in a Few Months
    • Rodri: Man City’s World Cup winner to undergo back surgery and may miss start of Premier League season | Football News
    • Opinion | Trump’s New Tariffs: Just as Bad as the Old Tariffs
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

    adminBy adminApril 14, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 14, 2026Vulnerability / Network Security

    ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

    A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild.

    The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0.

    It relates to a case of unrestricted file upload that stems from improper validation of file extension, allowing an attacker to upload arbitrary PHP files and achieve remote code execution.

    “[In] ShowDoc version before 2.8.7, an unrestricted and unauthenticated file upload issue is found and [an] attacker is able to upload a web shell and execute arbitrary code on server,” according to an advisory released by Vulhub. 

    Cybersecurity

    The vulnerability was addressed in ShowDoc version 2.8.7, which was shipped in October 2020. The current version of the software is 3.8.1.

    According to new details shared by Caitlin Condon, vice president of security research at VulnCheck, CVE-2025-0520 has come under active exploitation for the first time.

    The observed exploit involves leveraging the flaw to drop a web shell on a U.S.-based honeypot running a vulnerable version of ShowDoc. Data shared by the company shows that there are more than 2,000 instances of ShowDoc online, most of which are located in China.

    The development is the latest example of how threat actors are increasingly exploiting N-day security vulnerabilities, regardless of their install base. Users who are running ShowDoc are advised to update to the latest version for optimal protection.

    Actively CVE20250520 Exploited flaw RCE servers ShowDoc Unpatched
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleMillions of Rockstar Games business records stolen, hacking group says
    Next Article Two suspects have been arrested for allegedly shooting at Sam Altman’s house
    admin
    • Website

    Related Posts

    Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

    July 23, 2026

    Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

    July 23, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 23, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

    An OpenAI model went rogue on the internet and stole test answers 

    Trump Prepares Yet Another Strategy to Resurrect Global Tariffs

    The Best Vacuum for Pet Hair—We Tested Many to Find Which Ones Work Best (2026)

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by