INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

GeoServer Zero-Day Exploited in Active Attacks

| 2026-08-13 18:45 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
GeoServer's vulnerability to a zero-day SQL injection attack has been exposed, with attackers already probing exposed systems. The issue was publicly disclosed on August 15th and is currently being exploited by hundreds of probes from a small number of IP addresses within hours. GeoServer behind a VPN or reverse proxy can help mitigate the risk, but it's essential to follow best practices for securing the service. A patch has been released addressing the critical vulnerability, which carries a CVSS score of 9.8 out of 10.0.
Technical Mitigations AI-generated
* Implement a VPN or reverse proxy to restrict access to GeoServer instances, especially if they need to be publicly accessible. * Use IP allow-listing or other access-control mechanisms to limit the permissions available to the application's database account on exposed instances. * Treat public access to GeoServer as a temporary high-risk exception and closely monitor logs for unusual requests and database errors. * Consider restricting internet-facing instances of GeoServer, especially if they are not necessary for internal use, and restrict access to sensitive data or services.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

or•••••.geotools
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-36401CVE-2024-36401 CVE-2023-25158CVE-2023-25158 CVE-2023-25157CVE-2023-25157
Target & Sectors
Global Scope
Incident Timeline
‎February 2023
Threat actors used a known issue in the GeoTools library to target an unpatched version of GeoServer, exploiting a vulnerability that can lead to Remote Command Execution (RCE).
vulnerability CVE-2023-25158
organisation CVE-2023-25157
general_metric 9.8 score
organisation GeoTools
organisation Web Feature Service
organisation Lammerts
‎August 12, 2026
Threat actors used GeoServer to target and exploit a zero-day vulnerability in the sa Update, leading to unauthorized SQL injection.
organisation UTC
organisation GeoServer GeoTools
organisation CVSS
infrastructure 9.8 GeoServer GeoTools
infrastructure 3.0.1
infrastructure 2.28.5
infrastructure 2.27.6
organisation Update GeoServer
organisation GitHub
infrastructure 35.0
infrastructure 35.1
infrastructure 34.0
infrastructure 34.5
infrastructure 33.1
infrastructure 33.6
organisation Maven
organisation The Hacker News
organisation GeoServer
organisation DataStore
‎12 August 2026
Threat actors exploited a previously unknown zero-day vulnerability in GeoServer to target affected systems.
‎2026/08/13
Attackers used GeoServer behind a VPN to target the service, exploiting its SQL injection vulnerability.
organisation GeoServer GeoTools
organisation SQL
organisation Problem
organisation GeoServer
organisation CVE
organisation IP
organisation WatchTowr
organisation Put GeoServer
organisation SecurityAffairs
Tactical Metrics
Metrics
infrastructure
10
Geoserver Geotools
Metrics
infrastructure
‎3.0.1
Software Version
Metrics
infrastructure
‎2.28.5
Software Version
Metrics
infrastructure
‎2.27.6
Software Version
Metrics
infrastructure
‎35.0
Software Version
Metrics
infrastructure
‎35.1
Software Version
Metrics
infrastructure
‎34.0
Software Version
Metrics
infrastructure
‎34.5
Software Version
Metrics
infrastructure
‎33.1
Software Version
Metrics
infrastructure
‎33.6
Software Version
Intelligence Sources