Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Mirax Android RAT turns devices into SOCKS5 proxies and reaches 220,000 via meta ads

108 malicious Chrome extensions steal Google and Telegram data, affecting 20,000 users

How quantum science will shape our future

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » ShowDoc RCE flaw CVE-2025-0520 Actively exploited on unpatched servers
Identity

ShowDoc RCE flaw CVE-2025-0520 Actively exploited on unpatched servers

By April 14, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 14, 2026Vulnerability/Network Security

A critical security vulnerability affecting ShowDoc, a popular document management and collaboration service in China, is being exploited in the wild.

The vulnerability in question is CVE-2025-0520 (also known as CNVD-2020-26585), which has a CVSS score of 9.4 out of 10.0.

This is related to the unrestricted file upload case due to improper validation of file extensions, allowing an attacker to upload arbitrary PHP files and perform remote code execution.

”[In] An issue with unrestricted and unauthenticated file uploads was found in ShowDoc versions prior to 2.8.7. [an] According to an advisory released by Vulhub, an attacker can upload a web shell and execute arbitrary code on the server.

This vulnerability was resolved in ShowDoc version 2.8.7 shipped in October 2020. The current version of the software is 3.8.1.

According to new details shared by Caitlin Condon, VP of Security Research at VulnCheck, CVE-2025-0520 is being actively exploited for the first time.

The observed exploit involves leveraging this flaw to drop a web shell onto a US-based honeypot running a vulnerable version of ShowDoc. According to data shared by the company, there are more than 2,000 instances of ShowDoc online, most of them in China.

This development is the latest example of how threat actors are exploiting N-day security vulnerabilities regardless of their installed base. We recommend that users running ShowDoc update to the latest version for optimal protection.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAdded 6 known flaws exploited in CISA, Fortinet, Microsoft, and Adobe software.
Next Article Current and former commissioners convene leading clean energy experts for European Sustainable Energy Week 2026

Related Posts

Mirax Android RAT turns devices into SOCKS5 proxies and reaches 220,000 via meta ads

April 14, 2026

108 malicious Chrome extensions steal Google and Telegram data, affecting 20,000 users

April 14, 2026

Added 6 known flaws exploited in CISA, Fortinet, Microsoft, and Adobe software.

April 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Mirax Android RAT turns devices into SOCKS5 proxies and reaches 220,000 via meta ads

108 malicious Chrome extensions steal Google and Telegram data, affecting 20,000 users

How quantum science will shape our future

Using bubbles to remove PFAS from landfills

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.