• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
showdoc rce flaw cve 2025 0520 actively exploited on unpatched servers

ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

You are here: Home / General Cyber Security News / ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
April 14, 2026

A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild.

The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0.

It relates to a case of unrestricted file upload that stems from improper validation of file extension, allowing an attacker to upload arbitrary PHP files and achieve remote code execution.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“[In] ShowDoc version before 2.8.7, an unrestricted and unauthenticated file upload issue is found and [an] attacker is able to upload a web shell and execute arbitrary code on server,” according to an advisory released by Vulhub. 

Cybersecurity

The vulnerability was addressed in ShowDoc version 2.8.7, which was shipped in October 2020. The current version of the software is 3.8.1.

According to new details shared by Caitlin Condon, vice president of security research at VulnCheck, CVE-2025-0520 has come under active exploitation for the first time.

The observed exploit involves leveraging the flaw to drop a web shell on a U.S.-based honeypot running a vulnerable version of ShowDoc. Data shared by the company shows that there are more than 2,000 instances of ShowDoc online, most of which are located in China.

The development is the latest example of how threat actors are increasingly exploiting N-day security vulnerabilities, regardless of their install base. Users who are running ShowDoc are advised to update to the latest version for optimal protection.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «cisa adds 6 known exploited flaws in fortinet, microsoft, and CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
  • CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
  • JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025
  • FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts
  • ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
  • Your MTTD Looks Great. Your Post-Alert Gap Doesn’t
  • North Korea’s APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
  • OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
  • CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
  • Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621

Copyright © TheCyberSecurity.News, All Rights Reserved.