CVE-2026-22679
CVSS 9.8 CRITICAL: weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution… EPSS 20% (97th percentile).
Vulnerabilities & Exploits
A patched office automation server became a live command shell for attackers. In Weaver E-cology 10.0 builds before March 12, unauthenticated remote code execution let intruders run discovery commands on exposed servers, and patching is the only fix because the flaw sits in the product itself.
Vega says exploitation began in mid-March, five days after the vendor released a security update and two weeks before public disclosure. The affected product is Weaver E-cology, used for workflows, document management, HR, and internal business processes, mainly in Chinese organizations.
The timing suggests attackers either saw the fix early or reversed the patch fast enough to weaponize it within days. That makes vendor release windows a real exposure period, not a safe buffer, for any product where the patch lands before the advisory.
3 sources · May 5
CVSS 9.8 CRITICAL: weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution… EPSS 20% (97th percentile).
The Hacker News
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
MetInfo CMS flaw CVE-2026-29014 exploited after April 7 patch, enabling remote code execution and targeting 2,000 instances.
originalThe Hacker News
Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API
CVE-2026-22679 exploited via debug endpoint in Weaver E-cology before 20260312, enabling RCE and system compromise.
originalSecurityWeek
MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs
The security defects allow unauthenticated, remote attackers to execute arbitrary code through crafted requests.
originalPart of the PlainSec briefing for 2026-05-06
Every edition of this story: Weaver E-cology flaw turned servers into command shells