Multiple outlets report that threat actors are actively exploiting a critical remote code execution (RCE) vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation and collaboration platform. The flaw is tracked as CVE-2026-22679 and carries a reported CVSS score of 9.8. According to the reporting, attackers have used the vulnerability to run discovery commands and perform probing activity, indicating ongoing compromise attempts rather than isolated testing.

The vulnerability affects Weaver E-cology 10.0 versions prior to 20260312. The Hacker News coverage also describes the issue as unauthenticated, allowing remote exploitation without valid user credentials. It references an exposed debug-related API path involved in the exploitation process, including the endpoint “/papi/esearch/data/devops/…”.

Bleeping Computer states that exploitation has been observed since mid-March, with attacks continuing over time. Across the sources, the key points are that the bug is critical, reachable remotely without authentication, and is being used in real-world intrusion activity to execute commands and conduct discovery steps. The reporting does not indicate a specific group behind the activity.