Weaver E-cology critical bug exploited in attacks since March

2026-05-05T01:23:29Z26c691627ecd182f1e2283d3a204724f159571d0fb291e942dacaace37ca6041
authentication-bypassbackdoorcloud-email-abusecredential-theftcritical-vulnerabilitydata-breachexploitation-in-the-wildlinux-rootoauth-abusepackage-managementphishingransomwaresoftware-repository-compromisesupply-chain-compromisetelegram-fraud

What happened

Multiple high-impact incidents and active exploits reported: a critical Weaver E-cology vulnerability (CVE-2026-22679) has been exploited since March to run discovery commands, and a critical cPanel flaw (CVE-2026-41940) is being mass-exploited by "Sorry" ransomware operators. Other notable items include a critical authentication-bypass in MOVEit Automation (customers urged to patch), the "Copy Fail" Linux flaw now used to gain root, and a backdoored PyTorch Lightning PyPI package that drops a credential-stealer. Widespread abuse and fraud trends were also observed — Amazon SES is increasingly

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
26c691627ecd182f1e2283d3a204724f159571d0fb291e942dacaace37ca6041
Enrichment time
2026-05-05T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.