Hackers Target XWiki Flaw in Mass Internet Scanning
A critical remote code execution flaw in XWiki’s SolrSearch component has triggered a wave of exploitation attempts, as hackers target the XWiki flaw through mass internet scanning. The vulnerability permits attackers with guest-level access to execute arbitrary commands, posing a serious threat to organizations running the open-source enterprise wiki platform.
Though XWiki issued a patch and advisory in February, exploitation activity began rising only recently. Hackers target the XWiki flaw by crafting GET requests aimed at the SolrSearch RSS media endpoint. These requests embed Groovy commands that trigger shell execution, allowing full system compromise.
Security researchers observed attackers downloading malicious scripts from IP address 74.194.191.52, using the email bang2013@atomicmail.io as a User-Agent identifier. The associated server revealed links to Chicago rap references, but the intent remains unclear.
Organizations should urgently apply the February patch, monitor SolrSearch activity, and enforce network-level defenses to block exploitation.
Read the full report at
Hackers Actively Scanning Internet to Exploit XWiki Remote Code Execution Vulnerability
