Weaver E-cology critical bug exploited in attacks since March

2026-05-05T07:23:27Z3a253a20c344dfaf28d6b875798721fc241f7e2b2d01673308ec7b9962c8b412
active-exploitationauth-bypasscpanelcredential-theftdata-breachlinux-privilege-escalationmail-abusemoveitpackage-backdoorpatchingphishingransomwaresupply-chainweaver-e-cologywebapps

What happened

Multiple high-impact incidents and active exploits reported: a critical Weaver E-cology vulnerability (CVE-2026-22679) has been actively exploited since March for discovery activity; a critical cPanel flaw (CVE-2026-41940) is being mass-exploited in "Sorry" ransomware campaigns; Progress MOVEit Automation has a disclosed critical authentication-bypass issue prompting urgent patching; and the "Copy Fail" Linux vulnerability is being used in the wild to gain root. Additional threats include a backdoored PyTorch Lightning PyPI package dropping a credential stealer, growing abuse of Amazon SES for

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
3a253a20c344dfaf28d6b875798721fc241f7e2b2d01673308ec7b9962c8b412
Enrichment time
2026-05-05T07:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Weaver E-cology critical bug exploited in attacks since March · Baitaphish