CVE-2026-22679Active Exploitation(weaver / e-cology)

CRITICALCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 32 mentions and remains active

Immediate actions

  • Patch weaver e-cology systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking exposed debug functionality. Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-03-31 (UTC).

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • e-cology

Threat summary

  • Active exploitation appears in 57 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 74 mentions across 13 observed days

What's happening

  • Active exploitation reported across 57 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 65 signals
  • Disclosure: 11 classified signals
  • Peaked 7d ago at 32 mentions (2026-05-05); latest day: 1
  • 74 total mentions across 13 days

Affected systems

Vendors
Products
e-cology

Deep dive

Activity timeline74 mentions / 13d
08162432Mentions · 2026-04-07: 4Mentions · 2026-04-08: 1Mentions · 2026-04-13: 2Mentions · 2026-04-16: 1Mentions · 2026-05-04: 3Mentions · 2026-05-05: 32Mentions · 2026-05-06: 5Mentions · 2026-05-07: 13Mentions · 2026-05-08: 2Mentions · 2026-05-12: 3Mentions · 2026-05-17: 1Mentions · 2026-06-05: 6Mentions · 2026-06-25: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-05-05: 3PoC Mentioned / Linked · 2026-05-17: 1PoC Mentioned / Linked · 2026-06-25: 1Exploit Tool / Code · 2026-04-16: 1Exploit Tool / Code · 2026-05-05: 1Exploit Tool / Code · 2026-05-17: 1Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-05-04: 3Active Exploitation · 2026-05-05: 31Active Exploitation · 2026-05-06: 5Active Exploitation · 2026-05-07: 10Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-05-12: 2Active Exploitation · 2026-05-17: 1Active Exploitation · 2026-06-05: 1Active Exploitation · 2026-06-25: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 5Patch / Workaround · 2026-05-06: 5Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-17: 1Technical Details · 2026-04-07: 4Technical Details · 2026-04-08: 1Technical Details · 2026-04-13: 2Technical Details · 2026-04-16: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 27Technical Details · 2026-05-06: 5Technical Details · 2026-05-07: 12Technical Details · 2026-05-08: 1Technical Details · 2026-05-12: 3Technical Details · 2026-05-17: 1Technical Details · 2026-06-05: 6Technical Details · 2026-06-25: 104-0704-0804-1304-1605-0405-0505-0605-0705-0805-1205-1706-0506-25
Signal classification5 categories
Active Exploitation
5675.7%
Disclosure
1114.9%
Patch
45.4%
General
22.7%
Disclore
11.4%
Referenced assets37 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-074
Active Exploitation1Disclosure2Patch1
2026-04-081
Patch1
2026-04-132
Disclosure2
2026-04-161
Active Exploitation1
2026-05-043
Active Exploitation3
2026-05-0532
Active Exploitation31Patch1
2026-05-065
Active Exploitation4Patch1
2026-05-0713
Active Exploitation10Disclosure2General1
2026-05-082
Active Exploitation1Disclore1
2026-05-123
Active Exploitation2Disclosure1
2026-05-171
Active Exploitation1
2026-06-056
Active Exploitation1Disclosure4General1
2026-06-251
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Critical RCE flaw (CVE-2026-22679, CVSS 9.8) in Weaver E-cology 10.0 is under active exploitation. Attackers use unauthenticated requests to execute commands; activity observed since March 17–31, 2026, with failed payload drops & MSI attempts. Details 👉 https://thehackernews.com/2026/05/weaver-e-cology-rce-flaw-cve-2026-22679.html

    Post summary

    The post reports that CVE‑2026‑22679, a critical RCE in Weaver E‑cology 10.0, is actively exploited via unauthenticated command execution since mid‑March 2026, though no PoC, exploit code, or patch details are provided.

    32215869.4K
    1.8M followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Weaver E-cology 10.0 faces a critical 9.3 CVSS RCE (CVE-2026-22679). Unauthenticated attackers can hijack servers via a debug endpoint. Patch immediately! #WeaverEcology #CVE202622679 #RCE #CyberSecurity #InfoSec #Fanwei #ZeroDay #EnterpriseTech https://securityonline.info/weaver-ecology-rce-vulnerability-cve-2026-22679/ https://t.co/HPcqgFXbE2

    Post summary

    Weaver E‑cology 10.0 suffers a critical 9.3 CVSS remote code execution flaw (CVE-2026-22679) that allows unauthenticated hijacking via a debug endpoint; users are urged to patch immediately.

    15061708
    12.3K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 ثغرة تنفيذ عن بعد في Weaver E-cology CVE-2026-22679 يتم استغلالها بنشاط عبر واجهة API تعرضت منصة أتمتة المكاتب والتعاون المؤسسية Weaver (Fanwei) E-cology لثغرة أمنية حرجة يتم استغلالها بنشاط. تسمح الثغرة (CVE-2026-22679) بتنفيذ تعليمات عن بعد عبر واجهة API. يعود سبب حدوث ذلك إلى عدم كفاية التحقق من صحة المدخلات. تأثرت أنظمة ومؤسسات متعددة بهذه الثغرة. ولم يتم الإبلاغ عن إجراءات تصحيحية محددة حتى الآن. 🔗 للمزيد: https://thehackernews.com/2026/05/weaver-e-cology-rce-flaw-cve-2026-22679.html

    Post summary

    The post confirms that Weaver E-cology’s CVE-2026-22679—allowing remote code execution via its API—is being actively exploited, yet no patch or workaround has been publicly announced.

    000411.0K
    267 followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API https://thehackernews.com/2026/05/weaver-e-cology-rce-flaw-cve-2026-22679.html

    Post summary

    CVE-2026-22679 is a remote code execution flaw in Weaver E‑cology that is currently being actively exploited via its debug API.

    01022995
    158.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    TL;DR Weaver E-cology (a major Chinese enterprise office automation platform used by thousands of organizations) exposes an unauthenticated remote code execution flaw (CVE-2026-22679, CVSS 9.8) via a debug API endpoint. Active exploitation confirmed since March 2026. No…

    Post summary

    A major Chinese office automation platform suffers from an unauthenticated RCE flaw (CVE-2026-22679, CVSS 9.8) that is being actively exploited in the wild since March 2026.

    2001033
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Debug Port That Became a Weapon: Weaver E-cology CVE-2026-22679 Turns Debug API Into Enterprise RCE. Weaver E-cology, an enterprise office automation OA and collaboration platform widely deployed across Asia-Pacific organizations, suffers from a critical…

    Post summary

    The text announces a critical CVE‑2026‑22679 that turns Weaver E‑cology’s Debug API into a remote code execution vector.

    2001040
    246 followersView on X
  • Michael Martino@battista212
    Active Exploitation

    Critical RCE flaw in Weaver E-cology 10.0 (CVE-2026-22679, CVSS 9.8) is under active exploitation. Attackers using unauthenticated requests to execute commands. Activity observed since March 17-31, 2026, with failed payload drops and MSI attempts. #Cybersecurity https://t.co/dNbjJh6Rhi

    Post summary

    The tweet reports that CVE‑2026‑22679, a critical RCE in Weaver E‑cology 10.0, is actively exploited between March 17‑31, 2026 using unauthenticated requests.

    2001065
    227 followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API http://dlvr.it/TTD0ND #CyberSecurity #Vulnerability #CVE202622679 #RCE #Exploit https://t.co/pwqqnNkIxa

    Post summary

    The tweet reports that CVE‑2026‑22679, a Weaver E‑cology RCE flaw on a debug API, is actively exploited in the wild, with linked resources likely providing further details or PoC.

    000201.1K
    57.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2026-5865 3 - CVE-2026-0300 4 - CVE-2026-3854 5 - CVE-2026-22679 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top trending CVEs without providing any additional information or context about the vulnerabilities.

    00011215
    1.7K followersView on X
  • SoEmailSecurity@Soemailsecurity
    Active Exploitation

    Weaver E-cology's critical bug CVE-2026-22679 has been exploited since mid-March, allowing hackers to run discovery commands. Is your office automation system vulnerable? Get a Free email scan at http://soemailsecurity.com #EmailSecurity #CVE202622679 #OfficeAutomation

    Post summary

    The post claims CVE-2026-22679 has been actively exploited since March, enabling discovery commands on affected office automation systems, but no patches or PoC details are provided.

    1001046
    57 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Active Exploitation

    A critical Weaver E-cology unauthenticated RCE exploit (CVE-2026-22679) allows full system compromise. Active exploitation began March 17, 2026. https://www.redsecuretech.co.uk/blog/post/weaver-e-cology-unauthenticated-rce-exploit-under-active-attack/1157 #CVE #WeaverEcology #UnauthenticatedRCE #RemoteCodeExecution #Shadowserver #CriticalVulnerability #InfoSec https://t.co/GO3fbVEUz2

    Post summary

    Weaver E‐Ecology’s CVE‑2026‑22679 is an unauthenticated RCE that has been actively exploited since March 17 2026, enabling full system compromise. No mitigation or patch information is provided.

    01010101
    48 followersView on X
  • Upwind Security MDR@UpwindMDR
    Active Exploitation

    🚨 Critical - Weaver E-cology Unauth RCE (CVE-2026-22679) A vulnerability in the /papi/esearch/ endpoint of Weaver (Fanwei) E-cology allows unauthenticated remote code execution. Attackers can execute arbitrary OS commands by abusing exposed debug functionality through crafted POST requests. Active exploitation has been observed in the wild. 👉 Affected: Weaver E-cology 10.0 < 20260312 | Upgrade to 20260428

    Post summary

    CVE-2026-22679 enables unauthenticated remote code execution in Weaver E-cology’s /papi/esearch/ endpoint, is actively exploited, and can be mitigated by upgrading to version 20260428.

    0101086
    121 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22679 Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debu… https://www.cve.org/CVERecord?id=CVE-2026-22679

    Post summary

    The text announces CVE-2026-22679, highlighting an unauthenticated RCE vulnerability in Weaver (Fanwei) E-cology 10.0 before version 20260312.

    00020894
    57.7K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    The flaw: CVE-2026-22679 — CVSS score 9.8 Affected versions: Weaver E-cology 10.0 versions prior to March 12, 2026 (20260312) Attack vector: Network, unauthenticated Vulnerable endpoint: /papi/esearch/data/devops/dubboApi/debug/method

    Post summary

    The post lists basic technical details of CVE-2026-22679, such as score, affected versions, and endpoint, but does not provide evidence of a PoC, exploit, patch, or active attacks.

    1000033
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. The Debug Port That Became a Weapon: Weaver E-cology CVE-2026-22679 Turns Debug API Into Enterprise RCE

    Post summary

    The snippet announces CVE-2026-22679, describing it as enabling remote code execution through Weaver E-cology’s debug API, but provides no exploit or patch details.

    1000035
    246 followersView on X
  • AI Security Gateway@AISGateway
    Active Exploitation

    🔒 CVE-2026-22679 (CVSS 9.8) in Weaver E-cology is being actively exploited unauthenticated RCE via a debug API endpoint. No auth required. Full code execution. This is the pattern that keeps enterprise security teams up at night.

    Post summary

    CVE-2026-22679 in Weaver E-cology is actively exploited via an unauthenticated RCE through a debug API endpoint, allowing full code execution.

    1000022
    39 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Weaver E-cology の脆弱性 CVE-2026-22679 が FIX:実環境での積極的な悪用を確認 https://iototsecnews.jp/2026/05/05/critical-weaver-e-cology-rce-vulnerability-actively-exploited-in-attacks/ 今回の Weaver E-cology における脆弱性 CVE-2026-22679 の原因は、本来であれば外部からアクセスされるべきではないデバッグ・エンドポイントが公開状態に置かれていることにあります。この侵入口を通じて、攻撃者は認証をバイパスして、直接 OS に命令を送ることが可能となります。開発時に便利なツールであっても、それが実稼働環境に残ってしまうと、今回のような深刻なリスクを招くことがあります。ご利用のチームは、ご注意ください。 #CVE202622679 #Ecology #Exploit #Vulnerability #Weaver

    Post summary

    Weaver E‑cology CVE‑2026‑22679 is confirmed to be actively exploited via a publicly exposed debug endpoint that lets attackers bypass authentication and execute OS commands; no patch or PoC details are provided.

    01000132
    491 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-22679. 0day Intel: Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API https:/

    Post summary

    CVE-2026-22679 is a remote code execution flaw in Weaver E‑cology's Debug API that is currently being actively exploited, but no patch or workaround details are provided.

    1000047
    165 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Weaver E-cology. 0day Intel: Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API https:/

    Post summary

    The statement asserts that CVE-2026-22679, a remote code execution flaw in Weaver E-cology, is currently being actively exploited through the Debug API, with no PoC or patch details disclosed.

    1000052
    165 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: 🚨 Critical RCE flaw (CVE-2026-22679, CVSS 9.8) in Weaver E-cology 10.0 is under

    Post summary

    A critical remote code execution vulnerability (CVE‑2026‑22679, CVSS 9.8) was identified in Weaver E‑cology 10.0.

    1000046
    165 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appweavere-cology---

Explore more