CVE-2026-3965Active Exploitation

MEDIUMCVSS 2.1 · LOW

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file back/loaders/express.ts of the component API Interface. The manipulation of the argument command leads to protection mechanism failure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.20.2 is able to address this issue. The identifier of the patch is 6bec52dca158481258315ba0fc2f11206df7b719. It is advisable to upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days

What's happening

  • Active exploitation reported across 5 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-12); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-03-12: 2Mentions · 2026-04-29: 2Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-04: 1PoC Mentioned / Linked · 2026-04-29: 1Active Exploitation · 2026-04-29: 2Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-04: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-03-12: 1Technical Details · 2026-04-29: 2Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-04: 103-1204-2904-3005-0105-04
Signal classification2 categories
Active Exploitation
571.4%
Disclosure
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure2
2026-04-292
Active Exploitation2
2026-04-301
Active Exploitation1
2026-05-011
Active Exploitation1
2026-05-041
Active Exploitation1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Snyk warns of active in-the-wild exploitation of the Qinglong platform. Two authentication bypass flaws grant attackers RCE to deploy .fullgc cryptominers. #Qinglong #ExploitedInTheWild #CyberSecurity #InfoSec #Cryptomining #CVE #Snyk #ServerSecurity https://securityonline.info/qinglong-active-exploitation-in-the-wild-cve-2026-3965-cryptominer/ https://t.co/nAIxD0CQ4B

    Post summary

    Snyk reports that two authentication bypass bugs in Qinglong are actively being exploited in the wild to gain remote code execution and deploy cryptominers. No mitigation details or PoC are provided.

    01070468
    12.5K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Hackers exploited two auth bypass flaws (CVE-2026-3965 & CVE-2026-4047) in Qinglong task scheduler to deploy cryptominers via RCE starting Feb 7. Fix applied after initial mitigation proved insufficient. #Qinglong #RemoteExecution #China https://ift.tt/IQO6qTX

    Post summary

    Hackers exploited CVE-2026-3965 and CVE-2026-4047 via auth bypass to deploy cryptominers using RCE, with a fix later applied after mitigation failed.

    00010174
    4.1K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    BREAKING: Hackers exploit Qinglong RCE flaws CVE-2026-3965 and CVE-2026-4047 to drop .fullgc cryptominer on task scheduler servers running version 2.20.1 and earlier. https://threatcluster.io/cluster/cryptomining-attacks-exploit-rce-vulnerabilities-in-qinglong-47f2a003

    Post summary

    Hackers are actively exploiting two Qinglong RCE vulnerabilities (CVE-2026-3965 and CVE-2026-4047) to deploy a cryptominer on vulnerable task scheduler servers.

    1000037
    172 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: Qinglong Auth Bypass Chain to RCE - CVE-2026-3965 + CVE-2026-4047 (CVSS 9.3) chained for unauth RCE on Qinglong <= 2.20.1, dropping .fullgc cryptominer. 9 detections, 20 IOCs. https://intel.threadlinqs.com/#TL-2026-0441 #ThreatIntel #CyberSecurity #RCE #CVE https://t.co/PmenIBo9jX

    Post summary

    Threat intel reports that CVE-2026-3965 and CVE-2026-4047 have been chained via an authentication bypass to achieve unauthenticated RCE on Qinglong versions up to 2.20.1, with evidence of at least nine detections and 20 indicators of compromise.

    0000048
    37 followersView on X
  • Archange Shadow@Archange_Shadow
    Active Exploitation

    🚨 BREAKING: #BreakingNews Hackers exploit two authentication bypass vulnerabilities in Qinglong open-source task scheduler for cryptomining on servers. CVE-2026-3965 & CVE-2026-4047 enable unauthenticated RCE, deploying .fullgc miner causing 85-100% CPU usage. #Qinglong ... https://t.co/RM9TTPfDDJ

    Post summary

    The post reports that attackers are actively exploiting CVE-2026-3965 and CVE-2026-4047 in Qinglong to achieve unauthenticated RCE and run a cryptominer that spikes CPU usage.

    0000081
    385 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3965 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3965 #CVE-2026-3965 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/jgxPE73Xaz

    Post summary

    The tweet announces a new CVE (CVE-2026-3965) with medium severity, but offers no technical details, proof of concept, exploitation evidence, or mitigation information.

    0000035
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3965 A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file back/loaders/express.ts of the component API Int… https://www.cve.org/CVERecord?id=CVE-2026-3965

    Post summary

    The CVE‑2026‑3965 vulnerability has been identified in whyour qinglong up to version 2.20.1, affecting an unknown function in back/loaders/express.ts of the component API, with limited technical detail and no indication of exploitation or available patches.

    00000119
    56.7K followersView on X

Explore more