A critical security vulnerability in Weaver E-cology, an enterprise office automation and collaboration platform, is being actively exploited in the wild. The vulnerability CVE-2026-22679 has a CVSS score of 9.8 and allows unauthenticated remote code execution in Weaver E-cology versions prior to 20260312. The flaw is located in the debug API endpoint.
