Vulnerabilities

Hackers Exploiting Unpatched GeoServer Zero-Day

The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.

Zero-day vulnerability

Threat actors started exploiting an unpatched zero-day vulnerability in GeoServer hours after it was publicly disclosed, attack surface management firm WatchTowr says.

The security defect, described as an SQL injection issue that could be exploited to achieve remote code execution (RCE), was disclosed on Wednesday by a security researcher named q1uf3ng.

According to the researcher’s post on X, the flaw affects GeoServer’s jsonArrayContains function, a filter expression for querying JSON array fields to check if they contain specific values. It can be used with PostGIS and Oracle JDBC data stores.

The SQL injection is likely caused by user-supplied arguments being improperly sanitized before they are encoded into database queries, which, under certain configurations, leads to RCE.

According to WatchTowr, threat actors started exploiting the unpatched zero-day vulnerability shortly after it became public.

“Within hours of public disclosure, we began observing exploitation attempts and have since recorded hundreds of attempts originating from a small number of source IP addresses. Yet another example of how quickly attackers move once a vulnerability enters the public domain,” WatchTowr’s Jake Knott said.

Advertisement. Scroll to continue reading.

Threat actors have been targeting the security defect to probe vulnerable systems, but no follow-up activity has been observed.

“However, this is unlikely to remain the case for long: GeoServer has a track record of being targeted and exploited at scale, with multiple vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog,” Knott said.

“With no patch currently available and exploitation already underway, organizations running GeoServer should take this vulnerability seriously and, where possible, identify exposed instances, restrict public access, and monitor for a vendor fix,” he added.

A popular open source platform for sharing and processing geospatial data, GeoServer is used across government, agriculture, telecoms, transit, and other industries.

Related: Adobe Commerce Bug Targeted Immediately After Disclosure

Related: WordPress 7.0.4 Patches Remote Code Execution Vulnerability

Related: Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

Related: Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Related Content

Vulnerabilities

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.

Vulnerabilities

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.

Vulnerabilities

Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.

Vulnerabilities

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.

Vulnerabilities

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.

Vulnerabilities

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.

Vulnerabilities

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Vulnerabilities

The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version