ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

2026-04-14T07:24:13Z671e51035fa9e319e58dead6f75b39a0ce11b9bdc36ff6c0721af6191520c5a3
APT activityAdobe AcrobatAndroid SDKCISA KEVDDoSEngageLabFortinetGlassWormIDE compromiseJanelaRATMarimoPRISMEXRATSTX RATShowDocW3LL phishingactive exploitationbackdoored pluginbotnetknown exploited vulnerabilitiesmalware campaignsmisconfigured cloudphishing takedownrcesupply chain compromise

What happened

Multiple high-severity vulnerabilities and active exploitation campaigns reported by The Hacker News: a critical ShowDoc RCE (CVE-2025-0520/CNVD-2020-26585, CVSS 9.4) is being actively exploited on unpatched servers; CISA added several known-exploited flaws to its KEV list including CVE-2026-21643 (Fortinet); Adobe patched an Acrobat Reader flaw (CVE-2026-34621) under active exploitation; and Marimo RCE (CVE-2026-39987) was exploited within hours of disclosure. The feed also details multiple supply-chain and distribution incidents (CPUID compromise distributing STX RAT, backdoored Smart Slider

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
671e51035fa9e319e58dead6f75b39a0ce11b9bdc36ff6c0721af6191520c5a3
Enrichment time
2026-04-14T07:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.