A critical remote code execution (RCE) vulnerability in XWiki is being actively exploited by cybercriminals to deploy cryptocurrency mining malware (cryptominer) on compromised servers. XWiki is a popular open source wiki platform.

The vulnerability, tracked as CVE-2025-24893, allows unauthorized attackers to insert malicious templates and execute arbitrary code, completely bypassing authentication.
This discovery highlights the growing threat to web applications, where real-world attacks often outpace official notifications from organizations such as CISA's Known Exploitable Vulnerabilities (KEV) list
See also: Mem3nt0 Mori hackers use Chrome zero-day
VulnCheck reported exploitation of the vulnerability in question, based on data from their Canary network, which simulates vulnerable systems to detect attacks.
Unlike previous reports from Cyble, Shadow Server, and CrowdSec that noted simple exploit attempts, VulnCheck's observations reveal a sophisticated two-stage attack chain originating from an IP address in Vietnam.
The vulnerability, added to VulnCheck KEV in March 2025, involves template injection in XWiki's SolrSearch endpoint, allowing attackers to execute Groovy scripts to execute commands.

XWiki RCE Vulnerability: How does the attack work?
The attack unfolds in two phases, at least 20 minutes apart, to avoid detection.
See also: CISA: Fix exploited vulnerability in WSUS
In the initial request, the attackers send a URL-encoded GET to the SolrSearch endpoint, injecting an asynchronous Groovy payload that uses wget to download a downloader script (named x640) from a command and control (C2) server at 193.32.208.24:8080.
This script is stored in /tmp/11909 on the target system. The payload mimics normal browser traffic with a Firefox user agent.
About 20 minutes later, a second request executes the staged file by calling bash at /tmp/11909. The downloader then downloads two additional scripts, x521 and x522, which are piped directly to bash for execution, VulnCheck said.
These scripts manage the delivery of the payload: x521 creates directories in /var/tmp, downloads the tcrond coinminer from the same C2, and sets execution permissions.
Meanwhile, x522 cleans up the environment, killing competing miners like xmrig and kinsing, clears the history logs, and starts tcrond with a configuration that points to auto.c3pool.org on port 80.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The miner (UPX-packed for obfuscation) uses a address Monero wallet for payments, indicating a low-complexity but persistent operation.
See also: HashiCorp Vault: Vulnerabilities allow DoS attacks and authentication bypass
All traffic is traced back to the address 123.25.249.88, which has been flagged in multiple AbuseIPDB reports for abusive activity.
Protection
Defenders can use these indicators to look for similar activity on networks. The exploit uses transfer.sh to host payloads, a common tactic in cryptojacking campaigns.
Organizations using XWiki should immediately implement version 15.10.6 or later, monitor for strange wget traffic , and check for these indicators of violation (IOCs).
