Vulnerabilities & Exploits

Weaver E-cology flaw turned servers into command shells

A patched office automation server became a live command shell for attackers. In Weaver E-cology 10.0 builds before March 12, unauthenticated remote code execution let intruders run discovery commands on exposed servers, and patching is the only fix because the flaw sits in the product itself.

Vega says exploitation began in mid-March, five days after the vendor released a security update and two weeks before public disclosure. The affected product is Weaver E-cology, used for workflows, document management, HR, and internal business processes, mainly in Chinese organizations.

The timing suggests attackers either saw the fix early or reversed the patch fast enough to weaponize it within days. That makes vendor release windows a real exposure period, not a safe buffer, for any product where the patch lands before the advisory.

3 sources · May 5

CVE-2026-22679

NVD KEV

CVSS 9.8 CRITICAL: weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution… EPSS 20% (97th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-05

Every edition of this story: Weaver E-cology flaw turned servers into command shells

More from today