Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability

XWiki CVE-2025-24893 exploitation and miner deployment

Updated 18.11.2025 00:41
Case score 63
Members 1 First seen 29.10.2025 09:44 Latest activity 18.11.2025 00:41

Overview

**CVE-2025-24893** in **XWiki** is under active exploitation through requests to **/bin/get/Main/SolrSearch**, giving attackers remote code execution on exposed servers. Observed abuse uses an eval-injection weakness to stage a downloader, then a miner payload that kills competing miners and runs after a delay. VulnCheck reported canary hits, and CrowdSec and Cyble said exploitation was already underway by **March 2025**. CISA added the flaw to the KEV catalog and set a remediation due date of **2025-11-20**. Available evidence points to live cryptomining activity rather than isolated testing, but the broader scale of compromise is not known.
Latest development

VulnCheck reports active exploitation of XWiki CVE-2025-24893

VulnCheck said attackers are actively exploiting XWiki CVE-2025-24893, an eval injection flaw that can allow arbitrary remote code execution through a request to the "/bin/get/Main/SolrSearch" endpoint. The observed abuse targeted XWiki canaries from an attacker geolocated in Vietnam and used a two-stage workflow: wget retrieved the downloader "x640" from "193.32.208[.]24:8080" and wrote it to "/tmp/11909", then follow-on payloads "x521" and "x522" fetched a cryptocurrency miner, killed competing miners such as XMRig and Kinsing, and launched the miner with a c3pool.org configuration.

Signals

Exploitation
CVEs/products
Threat context

Malware & tooling context

2 families · 2 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability XWiki eval injection actively exploited remote code execution flaw (CVE-2025-24893)
Updated 29.10.2025 09:44 Lead Contribution 63
Exploitation Active Exploitation Exploit Public Exploit CVSS 9.8 Critical

The **XWiki** eval injection flaw **CVE-2025-24893** is being **actively exploited**, putting exposed servers at risk of **remote code execution** via **/bin/get/Main/SolrSearch**. Attackers are chaining the bug into a **two-stage** workflow that drops a downloader and ultimately installs a **cryptocurrency miner**. VulnCheck said it observed exploitation attempts against **XWiki canaries**, and real-world abuse has been reported since **March 2025**. Users should **apply updates as soon as possible** to reduce exposure.