ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
2026-04-14T07:24:13Z•671e51035fa9e319e58dead6f75b39a0ce11b9bdc36ff6c0721af6191520c5a3
APT activityAdobe AcrobatAndroid SDKCISA KEVDDoSEngageLabFortinetGlassWormIDE compromiseJanelaRATMarimoPRISMEXRATSTX RATShowDocW3LL phishingactive exploitationbackdoored pluginbotnetknown exploited vulnerabilitiesmalware campaignsmisconfigured cloudphishing takedownrcesupply chain compromise
What happened
Multiple high-severity vulnerabilities and active exploitation campaigns reported by The Hacker News: a critical ShowDoc RCE (CVE-2025-0520/CNVD-2020-26585, CVSS 9.4) is being actively exploited on unpatched servers; CISA added several known-exploited flaws to its KEV list including CVE-2026-21643 (Fortinet); Adobe patched an Acrobat Reader flaw (CVE-2026-34621) under active exploitation; and Marimo RCE (CVE-2026-39987) was exploited within hours of disclosure. The feed also details multiple supply-chain and distribution incidents (CPUID compromise distributing STX RAT, backdoored Smart Slider
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 671e51035fa9e319e58dead6f75b39a0ce11b9bdc36ff6c0721af6191520c5a3
- Enrichment time
- 2026-04-14T07:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.