INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GeoServer Zero-Day Exploited in Active Attacks
| 2026-08-13 18:45 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
GeoServer's vulnerability to a zero-day SQL injection attack has been exposed, with attackers already probing exposed systems. The issue was publicly disclosed on August 15th and is currently being exploited by hundreds of probes from a small number of IP addresses within hours. GeoServer behind a VPN or reverse proxy can help mitigate the risk, but it's essential to follow best practices for securing the service. A patch has been released addressing the critical vulnerability, which carries a CVSS score of 9.8 out of 10.0.
Technical Mitigations AI-generated
* Implement a VPN or reverse proxy to restrict access to GeoServer instances, especially if they need to be publicly accessible.
* Use IP allow-listing or other access-control mechanisms to limit the permissions available to the application's database account on exposed instances.
* Treat public access to GeoServer as a temporary high-risk exception and closely monitor logs for unusual requests and database errors.
* Consider restricting internet-facing instances of GeoServer, especially if they are not necessary for internal use, and restrict access to sensitive data or services.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
or•••••.geotools
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-36401CVE-2024-36401
CVE-2023-25158CVE-2023-25158
CVE-2023-25157CVE-2023-25157
Target & Sectors
Global Scope
Incident Timeline
February 2023
Threat actors used a known issue in the GeoTools library to target an unpatched version of GeoServer, exploiting a vulnerability that can lead to Remote Command Execution (RCE).
Click on any entity below to view its context and source!
vulnerability
CVE-2023-25158
The maintainers also noted that the vulnerability is a regression of
CVE-2023-25158
(CVSS score: 9.8), another
critical SQL injection vulnerability
that was addressed alongside CVE-2023-25157 in February 2023.
organisation
CVE-2023-25157
The maintainers also noted that the vulnerability is a regression of
CVE-2023-25158
(CVSS score: 9.8), another
critical SQL injection vulnerability
that was addressed alongside CVE-2023-25157 in February 2023.
general_metric
9.8 score
The maintainers also noted that the vulnerability is a regression of
CVE-2023-25158
(CVSS score: 9.8), another
critical SQL injection vulnerability
that was addressed alongside CVE-2023-25157 in February 2023.
organisation
GeoTools
When reached for comment, Jody Garnett, a project owner at GeoCat, told The Hacker News the vulnerability was a known issue in the GeoTools library and that it has been addressed in the aforementioned three versions of GeoServer.
organisation
Web Feature Service
This, in turn, can be turned into RCE by leveraging Web Feature Service (
WFS
) 1.0, which provides a path where a second PostgreSQL statement executes at the top level of the query.
organisation
Lammerts
"If GeoServer connects to PostgreSQL using a superuser or a role with pg_execute_server_program, this escalates to OS command execution on the database host," Lammerts explained.
August 12, 2026
Threat actors used GeoServer to target and exploit a zero-day vulnerability in the sa Update, leading to unauthorized SQL injection.
Click on any entity below to view its context and source!
organisation
UTC
It was
first disclosed
on August 12, 2026, at 10:46 UTC, by a researcher named @q1uf3ng on X. "GeoServer jsonArrayContains unauthorized SQL injection, and in the case of the sa
organisation
GeoServer GeoTools
In 2024, a critical security flaw impacting GeoServer GeoTools (
CVE-2024-36401
, CVSS score: 9.8) came under
active exploitation
to turn compromised devices into DDoS and cryptocurrency mining botnets, and residential proxies.
organisation
CVSS
In 2024, a critical security flaw impacting GeoServer GeoTools (
CVE-2024-36401
, CVSS score: 9.8) came under
active exploitation
to turn compromised devices into DDoS and cryptocurrency mining botnets, and residential proxies.
infrastructure
9.8 GeoServer GeoTools
In 2024, a critical security flaw impacting GeoServer GeoTools (
CVE-2024-36401
, CVSS score: 9.8) came under
active exploitation
to turn compromised devices into DDoS and cryptocurrency mining botnets, and residential proxies.
infrastructure
3.0.1
Update
GeoServer has released versions
3.0.1
,
2.28.5
, and
2.27.6
to address the critical SQL injection vulnerability, which has now been assigned the GitHub security advisory identifier "GHSA-mqjf-5f49-2fjh."
infrastructure
2.28.5
Update
GeoServer has released versions
3.0.1
,
2.28.5
, and
2.27.6
to address the critical SQL injection vulnerability, which has now been assigned the GitHub security advisory identifier "GHSA-mqjf-5f49-2fjh."
infrastructure
2.27.6
Update
GeoServer has released versions
3.0.1
,
2.28.5
, and
2.27.6
to address the critical SQL injection vulnerability, which has now been assigned the GitHub security advisory identifier "GHSA-mqjf-5f49-2fjh."
organisation
Update
GeoServer
Update
GeoServer has released versions
3.0.1
,
2.28.5
, and
2.27.6
to address the critical SQL injection vulnerability, which has now been assigned the GitHub security advisory identifier "GHSA-mqjf-5f49-2fjh."
organisation
GitHub
Update
GeoServer has released versions
3.0.1
,
2.28.5
, and
2.27.6
to address the critical SQL injection vulnerability, which has now been assigned the GitHub security advisory identifier "GHSA-mqjf-5f49-2fjh."
infrastructure
35.0
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
infrastructure
35.1
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
infrastructure
34.0
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
infrastructure
34.5
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
infrastructure
33.1
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
infrastructure
33.6
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
organisation
Maven
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
organisation
The Hacker News
"Currently, we're seeing attackers probe to identify vulnerable systems across the internet, triggering errors and not proceeding further," Jake Knott, principal security researcher at watchTowr, told The Hacker News in a statement.
organisation
GeoServer
"
In the absence of a patch, organizations running GeoServer are advised to identify exposed instances, restrict public access, and monitor for a vendor fix.
organisation
DataStore
"An SQL injection vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation: jsonArrayContains function," the project maintainers
said
in an alert, adding it requires PostGIS 12 or greater with a String or JSON field.
12 August 2026
Threat actors exploited a previously unknown zero-day vulnerability in GeoServer to target affected systems.
2026/08/13
Attackers used GeoServer behind a VPN to target the service, exploiting its SQL injection vulnerability.
Click on any entity below to view its context and source!
organisation
GeoServer GeoTools
In 2024, attackers used the critical GeoServer GeoTools vulnerability
CVE-2024-36401
(CVSS score of 9.8), to pull compromised systems into DDoS and cryptocurrency-mining botnets and residential proxy networks.
organisation
SQL
The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE).
That’s the Problem
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems.
organisation
Problem
That’s the Problem
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems.
organisation
GeoServer
A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet.
organisation
CVE
The vulnerability has yet to be assigned a CVE identifier.
organisation
IP
Within hours, watchTowr said it had begun seeing exploitation attempts, with hundreds of probes coming from a small number of IP addresses.
organisation
WatchTowr
Yet another example of how quickly attackers move once a vulnerability enters the public domain,”
said
WatchTowr’s Jake Knott.
organisation
Put GeoServer
Put GeoServer behind a VPN, a reverse proxy, IP allow-listing, or another access-control layer if the service does not need to be public.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, zero-day)
Tactical Metrics
Metrics
infrastructure
10
Geoserver Geotools
Click for context!
In 2024, a critical security flaw impacting GeoServer GeoTools (
CVE-2024-36401
, CVSS score: 9.8) came under
active exploitation
to turn compromised devices into DDoS and cryptocurrency mining botnets, and residential proxies.
Metrics
infrastructure
3.0.1
Software Version
Update
GeoServer has released versions
3.0.1
,
2.28.5
, and
2.27.6
to address the critical SQL injection vulnerability, which has now been assigned the GitHub security advisory identifier "GHSA-mqjf-5f49-2fjh."
Metrics
infrastructure
2.28.5
Software Version
Update
GeoServer has released versions
3.0.1
,
2.28.5
, and
2.27.6
to address the critical SQL injection vulnerability, which has now been assigned the GitHub security advisory identifier "GHSA-mqjf-5f49-2fjh."
Metrics
infrastructure
2.27.6
Software Version
Update
GeoServer has released versions
3.0.1
,
2.28.5
, and
2.27.6
to address the critical SQL injection vulnerability, which has now been assigned the GitHub security advisory identifier "GHSA-mqjf-5f49-2fjh."
Metrics
infrastructure
35.0
Software Version
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
Metrics
infrastructure
35.1
Software Version
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
Metrics
infrastructure
34.0
Software Version
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
Metrics
infrastructure
34.5
Software Version
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
Metrics
infrastructure
33.1
Software Version
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
Metrics
infrastructure
33.6
Software Version
"
The issue impacts the following versions of the Maven package "org.geotools:gt-jdbc-postgis" -
35.0 (Fixed in 35.1)
>=34.0 (Fixed in 34.5)
>=33.1 (Fixed in 33.6)
Intelligence Sources
Security Affairs
2026-08-15
GeoServer Zero-Day Is Already Being Probed. That’s the Problem
Security Affairs
The Hacker News
2026-08-13
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-18T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
GeoServer GeoTools
entity
9x
infrastructure
Software Version
3.0.1
version
4x
timeline
Temporal Reference
2024
date
3x
tactic
Cyber Operation Type
Ddos
tactic
3x
vulnerability
Exploited CVE
CVE-2024-36401
cve
3x
attribution
Attributing Entity
IP
authority
2x
general metric
Jdbc
34
jdbc
Contextual Telemetry
Context Block
7 METRICS
infrastructure
Geoserver Geotools
10
geoserver geotools
vulnerability
CVSS Score
10
score
general metric
Org.Geotools
35
org.geotools
general metric
Score
10
score
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Wfs
1
wfs
general metric
Jsonarraycontains(<Column
12
jsonarraycontains(<column
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.