A critical security vulnerability in Weaver E-cology is being actively exploited in cyberattacks, putting thousands of businesses worldwide at risk. The vulnerability, CVE-2026-22679, with a CVSS score of 9.8, allows for remote code execution unauthenticated, posing a serious threat to corporate systems. The severity of the situation is compounded by the fact that the platform is widely used in critical business functions, including the management of confidential corporate data and workflows.

Weaver E-cology is a widely used enterprise office automation and collaboration developed by Chinese company Fanwei. The platform is primarily used in business environments across Asia, particularly China, to manage corporate workflows, communication, and documents. The vulnerability affects Weaver E-cology versions 10.0 prior to 20260312.The fact that the platform manages sensitive business information and acts as a central hub for corporate communications makes the vulnerability particularly dangerous for organizations that use it.
According to the vulnerability description, the problem is located in the endpoint “/papi/esearch/data/devops/dubboApi/debug/method”. Attackers can create malicious POST requests with interfaceName and methodName controlled by them in order to reach command-execution helpers and achieve arbitrary command execution on the system.
See also: GitHub fixed critical RCE vulnerability in less than 6 hours
Weaver E-cology: Active exploitation of CVE-2026-22679 since March
According to The Hacker News, the Shadowserver Foundation noticed the first signs of active exploitation on March 31, 2026.Chinese security firm QiAnXin reported that it had successfully replicated the remote code execution vulnerability in an advisory issued on March 17, 2026.
In a report published last week, Vega Research Team identified active exploitation of CVE-2026-22679, with the first evidence of abuse dating back to March 17, 2026, five days after the release of the patches for the vulnerability. This shows that attackers moved extremely quickly to exploit unpatched systems. The time lag between the release of the patch and the start of the attacks highlights the importance of promptly applying security updates to critical systems.

Security researcher Daniel Messing explained that “the attack unfolded over the course of about a week, with the following activities: RCE, three failed payload installations, an attempted pivoting to an MSI implant that did not produce a working installation, and a small burst of attempts to retrieve PowerShell payloads from infrastructure controlled by the attacker.”
This detailed analysis of the attack reveals a methodical approach by the attackers, who persisted despite initial setbacks, indicating a high level of interest in their targets.
See also: Flowise: Critical vulnerability allows RCE via MCP Adapters
Technical details and attack methods
The MSI installer, according to the Israeli cybersecurity firm, used the name “fanwei0324.msi”, indicating an attempt to pass off the malicious payload as harmless (using the romanized Chinese name for Weaver). The unknown perpetrator also executed discovery commands, such as whoami, ipconfig and tasklist, throughout the campaign. These commands are typical steps that attackers use to understand the target’s environment and plan further moves.
Protection measures and security recommendations
To address the threat of CVE-2026-22679, organizations should take immediate action. First, implementing the update is critical and should be treated as an urgent priority. Second, system administrators should implement temporary measures such as using Web Application Firewalls (WAF) to block requests to the affected endpoint. Third, network monitoring for anomalous traffic to Weaver E-cology can help detect exploitation attempts early.
See also: Critical vulnerability fixed in SAP NetWeaver

Additionally, security researcher Kerem Oruc has released a Python-based detection script that detects vulnerable Weaver E-cology by checking whether the sensitive API endpoint is accessible. This tool can help system administrators quickly assess their exposure to the vulnerability. Additionally, organizations should implement least privilege principles for web applications and ensure that debug endpoints are removed or properly protected in production environments.
The active exploitation of this critical vulnerability highlights the urgent need for immediate action by all organizations using Weaver E-cology.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
