ThreatCluster[verified]@threatclusterActive Exploitation
Hackers are actively exploiting two Qinglong RCE vulnerabilities (CVE-2026-3965 and CVE-2026-4047) to deploy a cryptominer on vulnerable task scheduler servers.
ThreadLinqs[verified]@threadlinqsActive Exploitation
Threat intel reports that CVE-2026-3965 and CVE-2026-4047 have been chained via an authentication bypass to achieve unauthenticated RCE on Qinglong versions up to 2.20.1, with evidence of at least nine detections and 20 indicators of compromise.
Archange Shadow[verified]@Archange_ShadowActive Exploitation
The post reports that attackers are actively exploiting CVE-2026-3965 and CVE-2026-4047 in Qinglong to achieve unauthenticated RCE and run a cryptominer that spikes CPU usage.
Gray Hats@the_yellow_fallActive Exploitation
Snyk reports that two authentication bypass bugs in Qinglong are actively being exploited in the wild to gain remote code execution and deploy cryptominers. No mitigation details or PoC are provided.
Cybersecurity News Everyday@TweetThreatNewsActive Exploitation
Hackers exploited CVE-2026-3965 and CVE-2026-4047 via auth bypass to deploy cryptominers using RCE, with a fix later applied after mitigation failed.
CVEarity@CVEarityDisclosure
The tweet announces a new CVE (CVE-2026-3965) with medium severity, but offers no technical details, proof of concept, exploitation evidence, or mitigation information.
CVE@CVEnewDisclosure
The CVE‑2026‑3965 vulnerability has been identified in whyour qinglong up to version 2.20.1, affecting an unknown function in back/loaders/express.ts of the component API, with limited technical detail and no indication of exploitation or available patches.