Misbar | مسبار[verified]@MisbarSecActive Exploitation
The post confirms that Weaver E-cology’s CVE-2026-22679—allowing remote code execution via its API—is being actively exploited, yet no patch or workaround has been publicly announced.
Nicolas Krassas[verified]@DinosnActive Exploitation
CVE-2026-22679 is a remote code execution flaw in Weaver E‑cology that is currently being actively exploited via its debug API.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
A major Chinese office automation platform suffers from an unauthenticated RCE flaw (CVE-2026-22679, CVSS 9.8) that is being actively exploited in the wild since March 2026.
Lyrie.ai[verified]@lyrie_aiDisclosure
The text announces a critical CVE‑2026‑22679 that turns Weaver E‑cology’s Debug API into a remote code execution vector.
Michael Martino[verified]@battista212Active Exploitation
The tweet reports that CVE‑2026‑22679, a critical RCE in Weaver E‑cology 10.0, is actively exploited between March 17‑31, 2026 using unauthenticated requests.
Blue Team News[verified]@blueteamsec1Active Exploitation
The tweet reports that CVE‑2026‑22679, a Weaver E‑cology RCE flaw on a debug API, is actively exploited in the wild, with linked resources likely providing further details or PoC.
Upwind Security MDR[verified]@UpwindMDRActive Exploitation
CVE-2026-22679 enables unauthenticated remote code execution in Weaver E-cology’s /papi/esearch/ endpoint, is actively exploited, and can be mitigated by upgrading to version 20260428.
Lyrie.ai[verified]@lyrie_aiGeneral
The post lists basic technical details of CVE-2026-22679, such as score, affected versions, and endpoint, but does not provide evidence of a PoC, exploit, patch, or active attacks.