The RondoDox botnet has been actively exploiting a critical vulnerability in unpatched XWiki servers, identified as CVE-2025-24893, which allows arbitrary remote code execution via the /bin/get/Main/SolrSearch endpoint. This flaw, rated with a CVSS score of 9.8, was patched in XWiki versions 15.10.11, 16.4.1, and 16.5.0RC1, but many instances remain exposed. Since late October 2025, there has been a significant increase in exploitation attempts, with attackers leveraging the vulnerability to deploy cryptocurrency miners, establish reverse shells, and conscript devices into the RondoDox botnet for distributed denial-of-service (DDoS) attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-24893 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply mitigations by November 20.
VulnCheck reports that multiple independent threat actors, including RondoDox, are targeting this vulnerability using custom tooling, bespoke scanners, and well-documented payload servers. The first RondoDox exploit was observed on November 3, 2025, and activity has continued to escalate, with clear attribution based on unique HTTP User-Agent strings and payload naming conventions. The surge in attacks underscores the urgent need for organizations to patch affected XWiki instances and implement early detection measures to prevent compromise and further botnet expansion.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
By mid-November 2025, public reporting tied CVE-2025-24893 exploitation to RondoDox, cryptominer operators, and other attackers using public exploit methods such as Nuclei templates. The reporting highlighted active abuse of unpatched XWiki servers and published IoCs for defenders.
A second major spike in attacks against vulnerable XWiki servers was observed on November 11. Campaigns included botnet enrollment, cryptocurrency miner deployment, and reverse shell attempts.
Researchers observed a notable increase in scanning and exploitation attempts targeting CVE-2025-24893 on November 7. The activity indicated broader adoption of the flaw by multiple malicious actors.
VulnCheck observed RondoDox botnet activity targeting vulnerable XWiki instances starting on November 3. The botnet used crafted requests to inject Groovy code and pull compromised servers into its DDoS infrastructure.
CISA marked the XWiki flaw as actively exploited and added it to the Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies were ordered to remediate by November 20, 2025.
The vulnerability was patched in XWiki versions 15.10.11, 16.4.1, and 16.5.0RC1. These releases addressed the critical eval injection bug enabling remote code execution.
Multiple sources say exploitation of the XWiki vulnerability began no later than March 2025. Different attackers used the flaw for arbitrary code execution, including reverse shells and malware deployment.
Reports describe CVE-2025-24893, an eval injection remote code execution flaw in XWiki, as having been left unpatched since February 2025. The bug affects XWiki versions prior to the later fixed releases.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.