CRITICALVulnerability
Global

ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

·Source: The Hacker News

Updated:

Executive Summary

A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0. It relates to a case of unrestricted file upload that stems from improper validation of

Analysis

A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0. It relates to a case of unrestricted file upload that stems from improper validation of

Indicators of Compromise (1)

CVE (1)
CVE-2025-0520
Source Attribution

Originally published by The Hacker News on Apr 14, 2026.

Related Threats