Weaver E-cology Critical Vulnerability Active Exploitation | MSSP Advisory
Critical
DateMay 6, 2026
📋Executive Summary
Attackers are actively exploiting a critical vulnerability in Weaver E-cology, a Chinese workflow and document management platform. Vega documented active attacks targeting organizations primarily in China that use this platform for internal business processes. The exploitation grants attackers access to workflow systems and document repositories.
⚠️Why It Matters for MSSPs
Your clients running Weaver E-cology face immediate compromise of their workflow systems and document stores, potentially exposing sensitive business data and internal processes. Any MSSP managing environments with this platform needs to act within hours to prevent client breaches that could trigger contract violations and retention issues.
✅Recommended Action
Inventory all client environments for Weaver E-cology installations and immediately isolate those systems from network access until patches can be applied.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.