
Critical RCE Vulnerability in Weaver E-cology Being Actively Exploited
CybersecurityVulnerabilitiesRemoteCodeExecutionEnterpriseSoftware
A critical remote code execution (RCE) vulnerability (CVE-2026-22679, CVSS score: 9.8) in Weaver E-cology, an enterprise office automation and collaboration platform, is being actively exploited in the wild. The flaw affects Weaver E-cology version 10.0 releases prior to 20260312 and stems from an unauthenticated access issue in the "/papi/esearch/data/devops/" endpoint. No additional technical details about the exploitation mechanism or threat actors were provided. The vulnerability enables unauthenticated attackers to execute arbitrary code remotely. Weaver has not issued a public statement regarding mitigation or patch availability within the reported content.