Friday, September 11, 2026

XWiki Remote Code Execution Flaw Actively Weaponized for Coinmining

A critical security vulnerability in XWiki collaboration software is being actively exploited by threat actors to deploy cryptocurrency mining malware on vulnerable systems.

The flaw, tracked as CVE-2025-24893, represents a serious threat to organizations running unpatched XWiki installations.

Cybersecurity researchers at VulnCheck have captured concrete evidence of active exploitation through their canary network.

CVE DetailsInformation
CVE IDCVE-2025-24893
Vulnerability TypeUnauthenticated Remote Template Injection
Affected ProductXWiki
SeverityCritical

The attacks originate from Vietnam-based threat actors who employ a sophisticated two-stage attack methodology.

The initial exploitation occurs through XWiki’s SolrSearch endpoint, where attackers inject malicious code via a template injection vulnerability that requires no authentication.

The attack begins when hackers send a crafted request to the vulnerable endpoint, using URL-encoded parameters to execute remote commands.

The first stage downloads a small bash script from a command-and-control server located at IP address 193.32.208.24, which hosts malicious payloads through a transfer.sh instance.

This downloader is saved to the /tmp directory on compromised systems. After approximately 20 minutes, attackers return with a second request that executes the staged downloader, initiating the full infection chain.

The downloaded script immediately fetches two additional payloads that work together to establish persistence and deploy the mining operation.

One script installs a cryptocurrency miner called tcrond in a hidden directory, while the second script terminates competing miners and launches the malicious mining software configured to connect with c3pool.org mining pools.

Despite confirmed exploitation in the wild, CVE-2025-24893 notably does not appear on CISA’s Known Exploited Vulnerabilities catalog, highlighting a concerning gap between real-world attacks and official recognition.

VulnCheck added the vulnerability to their own KEV database in March 2025 after multiple security organizations including Cyble, Shadow Server, and CrowdSec reported exploitation attempts.

The mining malware deployed in these attacks is UPX-packed to evade detection and employs several anti-analysis techniques.

Once activated, the miner attempts to kill other cryptocurrency mining processes on the system, removes command history, and disables bash history logging to cover its tracks.

Security researchers identified the primary attack infrastructure at IP address 123.25.249.88, which has multiple reports on AbuseIPDB for malicious activity.

Organizations running XWiki should immediately update to patched versions and monitor their systems for indicators of compromise.

Network administrators should block communication with the identified malicious IP addresses and search for the specific file hashes associated with this campaign.

The vulnerability’s remote nature and lack of authentication requirements make it particularly dangerous for internet-facing XWiki installations.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News