CVE-2026-22679
CVSS 9.8 CRITICAL: weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution… EPSS 20% (97th percentile).
Vulnerabilities · 132 days ago
A patched office automation server became a live command shell for attackers. In Weaver E-cology 10.0 builds before March 12, unauthenticated remote code execution let intruders run discovery commands on exposed servers, and patching is the only fix because the flaw sits in the product itself.
Vega says exploitation began in mid-March, five days after the vendor released a security update and two weeks before public disclosure. The affected product is Weaver E-cology, used for workflows, document management, HR, and internal business processes, mainly in Chinese organizations.
The timing suggests attackers either saw the fix early or reversed the patch fast enough to weaponize it within days. That makes vendor release windows a real exposure period, not a safe buffer, for any product where the patch lands before the advisory.
CVSS 9.8 CRITICAL: weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution… EPSS 20% (97th percentile).
3 sources covering this story
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
MetInfo CMS flaw CVE-2026-29014 exploited after April 7 patch, enabling remote code execution and targeting 2,000 instances.
Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API
CVE-2026-22679 exploited via debug endpoint in Weaver E-cology before 20260312, enabling RCE and system compromise.
MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs
The security defects allow unauthenticated, remote attackers to execute arbitrary code through crafted requests.
Weaver E-cology critical bug exploited in attacks since March
Hackers have been exploiting a critical vulnerability (CVE-2026-22679) in the Weaver E-cology office automation since mid-March to run discovery commands.
Part of the PlainSec briefing for 2026-05-06