Two critical server-side vulnerabilities have exposed widely deployed web applications to full remote compromise without authentication. In AVideo, CVE-2025-34433 was rated CVSS 10.0 after researchers reported a deterministic cryptographic failure that enables immediate remote code execution during normal HTTP request processing. Successful exploitation can grant attackers the privileges of the web server process, with broad read and write access to the application directory, internal database, and uploaded media, creating a complete confidentiality, integrity, and availability failure. The flaw is considered highly reliable because it does not depend on memory corruption and is not meaningfully hindered by mitigations such as ASLR, DEP, or stack canaries; reports also noted the existence of weaponized exploit modules.
A separate actively exploited flaw, CVE-2026-22679, affects Weaver (Fanwei) E-cology 10.0 builds before 20260312. The vulnerability stems from an exposed debug endpoint that forwards attacker-controlled JSON into the Dubbo RPC framework without authentication or validation, allowing arbitrary operating system command execution through the Java application running under Tomcat. Threat intelligence tied exploitation to internet-facing systems shortly after the vendor patch, with observed activity including ping-based verification, PowerShell payload retrieval, attempted MSI deployment, and evasive techniques such as renamed PowerShell binaries and in-memory execution. Defenders were urged to upgrade affected systems, watch for suspicious child processes spawned by java.exe, and review EDR telemetry for obfuscated or fileless post-exploitation behavior.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Cyberpress reported that CVE-2026-22679 was being actively exploited against vulnerable Weaver E-cology 10.0 instances and urged organizations to upgrade, hunt for suspicious java.exe child processes, and block known malicious infrastructure.
A report disclosed CVE-2025-34433 in AVideo as a critical unauthenticated remote code execution flaw caused by cryptographic failures, with a CVSS v4.0 score of 10.0. The issue enables reliable code execution with web server privileges and broad access to the application directory, database, and uploaded media.
Threat intelligence indicates exploitation of the Weaver E-cology flaw was underway by 2026-03-17. Observed activity included ping-based verification, PowerShell payload retrieval, attempted MSI deployment, and evasive execution techniques on an internet-facing Windows server.
Weaver (Fanwei) patched CVE-2026-22679 in E-cology 10.0 builds on 2026-03-12 by removing the exposed debug endpoint that allowed unauthenticated command execution through Dubbo RPC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.