- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,316
The attackers began to act long before the problem was officially announced.

Hackers began using a critical gap in Weaver E-cology just days after the correction is released. The attacks went covertly and did not look like a mass campaign, but the scenario shows how quickly the attackers check corporate systems for fresh weaknesses.
We are talking about CVE-2026-22679 – error of remote code execution in Weaver E-cology 10.0 in the assemblies until March 12, 2026. The platform is widely used for office automation, document management, HR processes and internal work scenarios of many organizations.
Weaver released a March 12 fix, but publicly disclosed the details later. According to the Vega team, the first attacks began about five days after the release of the update and two weeks before the official notification. The activity lasted about a week and took place in several stages.
The problem was related to an open debugging API. Such an interface without authorization passed the user settings to server RPC functions and did not check the input. As a result, the attackers could transmit specially prepared values, which the server performed as system commands. A similar vector – the absence of checking input without prior authorization – was used in October 2025 when attacked on WatchGuard devices.
At first, the attackers checked the possibility of remote code execution through the ping commands from the Java process to the callback address associated with Goby. Then came attempts to download PowerShell scenarios, but end-bodied protections blocked these actions.
After unsuccessful downloads, the attackers tried to launch the MSI installer “fanwei0324.msi”, selected for a specific target. The file did not work correctly, and Vega experts did not see further activity through this path.
Later, the attackers returned to a vulnerable RCE-interface and applied a osteocated PowerShell without writing files to the disk to re-receive deleted scripts. At all stages, intelligence teams were launched, including whoami, ipconfig and tasklist.
Vega clarifies that all noticed processes were launched from “java.exe”, that is, from the Java machine built into the Tomcat in the Weaver. There were no signs of prior authorization. Despite the ability to execute the code, the attackers did not gain a foothold on the attacked host and did not create a stable session.
The official bulletin does not specify the workaround. Users Weaver E-cology 10.0 are recommended to install the current build as soon as possible, since the version 20260312 completely removes the dangerous debugging interface.

Hackers began using a critical gap in Weaver E-cology just days after the correction is released. The attacks went covertly and did not look like a mass campaign, but the scenario shows how quickly the attackers check corporate systems for fresh weaknesses.
We are talking about CVE-2026-22679 – error of remote code execution in Weaver E-cology 10.0 in the assemblies until March 12, 2026. The platform is widely used for office automation, document management, HR processes and internal work scenarios of many organizations.
Weaver released a March 12 fix, but publicly disclosed the details later. According to the Vega team, the first attacks began about five days after the release of the update and two weeks before the official notification. The activity lasted about a week and took place in several stages.
The problem was related to an open debugging API. Such an interface without authorization passed the user settings to server RPC functions and did not check the input. As a result, the attackers could transmit specially prepared values, which the server performed as system commands. A similar vector – the absence of checking input without prior authorization – was used in October 2025 when attacked on WatchGuard devices.
At first, the attackers checked the possibility of remote code execution through the ping commands from the Java process to the callback address associated with Goby. Then came attempts to download PowerShell scenarios, but end-bodied protections blocked these actions.
After unsuccessful downloads, the attackers tried to launch the MSI installer “fanwei0324.msi”, selected for a specific target. The file did not work correctly, and Vega experts did not see further activity through this path.
Later, the attackers returned to a vulnerable RCE-interface and applied a osteocated PowerShell without writing files to the disk to re-receive deleted scripts. At all stages, intelligence teams were launched, including whoami, ipconfig and tasklist.
Vega clarifies that all noticed processes were launched from “java.exe”, that is, from the Java machine built into the Tomcat in the Weaver. There were no signs of prior authorization. Despite the ability to execute the code, the attackers did not gain a foothold on the attacked host and did not create a stable session.
The official bulletin does not specify the workaround. Users Weaver E-cology 10.0 are recommended to install the current build as soon as possible, since the version 20260312 completely removes the dangerous debugging interface.