← العودة للجدول
CVE-2026-3965
Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomining
📅 2026-04-27 03:00:00
🔴 Critical 🔥 Yes Snyk Blog Malware Malware 🎯 EPSS 0.12%

📋 الوصف الكامل

Two authentication bypass vulnerabilities (CVE-2026-3965, CVE-2026-4047) in the Qinglong task scheduling panel were exploited in the wild to deploy cryptomining malware. Here's what happened, how the attacks worked, and what self-hosted application operators should learn from this incident.

💻 الأنظمة المتأثرة

Qinglong task scheduler

⚠️ نوع التهديد

Malware

🔗 CVE ID

CVE-2026-3965

📡 المصدر

Snyk Blog

✅ الحلول والتخفيف

Refer to CVE-2026-3965 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←