RondoDox botnet exploitation of XWiki CVE-2025-24893
Malware Activity
Summary
Hide ▲
Show ▼
The RondoDox botnet has begun targeting unpatched XWiki instances through CVE-2025-24893, expanding its reach and putting vulnerable servers at risk of botnet recruitment and follow-on payload delivery. The flaw can enable arbitrary code execution through the `/bin/get/Main/SolrSearch` endpoint. Activity was observed in November 2025 after exploitation had already been seen in the wild since at least March.
Related Happenings
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation Wave
H score87
First: 05.06.2026 11:38
Last: 05.06.2026 11:38
Sources 1
About this happening:
Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation WaveAbout this happening: Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...
Magento exploitation wave for CVE-2026-45247
Exploitation Wave
H score9
First: 04.06.2026 10:19
Last: 04.06.2026 10:19
Sources 1
About this happening:
Active exploitation of CVE-2026-45247 is hitting Mirasvit Cache Warmer on Magento stores, with malicious requests carrying serialized PHP payloads that can lead to r...
Magento exploitation wave for CVE-2026-45247
Exploitation WaveAbout this happening: Active exploitation of CVE-2026-45247 is hitting Mirasvit Cache Warmer on Magento stores, with malicious requests carrying serialized PHP payloads that can lead to r...
MetInfo CMS unauthenticated PHP code injection actively exploited remote code execution flaw (CVE-2026-29014)
Vulnerability
H score53
First: 05.05.2026 14:56
Last: 05.05.2026 14:56
Sources 1
About this happening:
CVE-2026-29014 in MetInfo CMS is actively exploited, putting versions 7.9, 8.0, and 8.1 at risk of remote code execution and full server takeover. MetInfo...
MetInfo CMS unauthenticated PHP code injection actively exploited remote code execution flaw (CVE-2026-29014)
VulnerabilityAbout this happening: CVE-2026-29014 in MetInfo CMS is actively exploited, putting versions 7.9, 8.0, and 8.1 at risk of remote code execution and full server takeover. MetInfo...
Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign
Campaign
H score38
First: 22.04.2026 23:04
Last: 22.04.2026 23:04
Sources 1
About this happening:
The Mirai-based malware campaign is actively exploiting CVE-2025-29635 against D-Link DIR-823X routers, turning vulnerable devices into botnet nodes. The activity matt...
Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign
CampaignAbout this happening: The Mirai-based malware campaign is actively exploiting CVE-2025-29635 against D-Link DIR-823X routers, turning vulnerable devices into botnet nodes. The activity matt...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
Vulnerability
H score1
First: 20.04.2026 16:01
Last: 20.04.2026 16:01
Sources 1
About this happening:
The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
VulnerabilityAbout this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
Timeline
-
15.11.2025 18:35 2 articles · 8mo ago
RondoDox first exploit of XWiki CVE-2025-24893
Exploitation ObservedRondoDox botnet malware was first observed targeting unpatched XWiki instances through CVE-2025-24893 on November 3, 2025, using the /bin/get/Main/SolrSearch endpoint to pursue arbitrary code execution against exposed servers.
Show sources
- RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet — thehackernews.com — 15.11.2025 18:35
- RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet — thehackernews.com — 15.11.2025 18:35
-
15.11.2025 18:35 2 articles · 8mo ago
Broader CVE-2025-24893 exploitation pressure on XWiki
Campaign Scope UpdateVulnCheck described a broader wave of CVE-2025-24893 exploitation against XWiki, with attempts hitting a new high on November 7 and another surge on November 11, alongside RondoDox botnet activity, cryptocurrency miner delivery, reverse-shell attempts, and Nuclei-based probing. The flaw is an eval-injection bug that can enable arbitrary remote code execution through /bin/get/Main/SolrSearch, XWiki patched it in 15.10.11, 16.4.1, and 16.5.0RC1 in late February 2025, and CISA added it to the KEV catalog with a November 20 mitigation deadline for federal agencies.
Show sources
- RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet — thehackernews.com — 15.11.2025 18:35
- RondoDox botnet malware now hacks servers using XWiki flaw — www.bleepingcomputer.com — 18.11.2025 00:41