Attackers are actively exploiting a critical ShowDoc vulnerability, CVE-2025-0520 (also referenced as CNVD-2020-26585), to compromise unpatched servers exposed to the internet. The flaw affects ShowDoc versions before 2.8.7 and stems from an unauthenticated unrestricted file upload weakness that lets attackers upload arbitrary PHP files, plant web shells, and achieve remote code execution; it carries a CVSS score of 9.4.
Researchers reported observed exploitation against a vulnerable U.S.-based honeypot, where attackers dropped a web shell after targeting the application. More than 2,000 internet-exposed ShowDoc instances were identified online, most of them in China, underscoring the continued risk from older N-day vulnerabilities that remain unpatched years after a fix was released in ShowDoc 2.8.7; the current version is 3.8.1, and users are being urged to upgrade and lock down exposed systems.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers said more than 2,000 internet-exposed ShowDoc instances were still reachable online, with most located in China. The exposure increased the risk that unpatched systems could be compromised through the actively exploited vulnerability.
VulnCheck researcher Caitlin Condon reported the first observed in-the-wild exploitation of the ShowDoc flaw, including an attack that dropped a web shell on a U.S.-based honeypot running a vulnerable instance. The activity showed attackers were targeting unpatched internet-exposed ShowDoc servers.
ShowDoc addressed an unauthenticated unrestricted file upload vulnerability affecting versions before 2.8.7 with the release of version 2.8.7. The flaw, later tracked as CVE-2025-0520 and also identified as CNVD-2020-26585, can allow attackers to upload PHP files and achieve remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.