CVE-2025-58360 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 28, 2025
Last Seen
September 2, 2026

Related Threat Clusters

  • GeoNetwork Vulnerabilities Enable Unauthenticated RCE Attacks

    GeoNetwork, an open-source geospatial metadata catalog, has two vulnerabilities that can be exploited to achieve unauthenticated remote code execution (RCE). The flaws, CVE-2026-63219 and CVE-2026-58400, allow attackers…

    2 articles · Updated September 2, 2026
  • GeoServer XXE Vulnerability Exploited in Cyber Attacks

    A recently discovered vulnerability in GeoServer, identified as CVE-2025-58360, allows attackers to exploit insufficiently sanitized user input to define external entities within XML requests. This flaw has been…

    3 articles · Updated December 12, 2025

Recent Intelligence Reports

  • GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends — Thehackernews · September 2, 2026
  • Recent GeoServer Vulnerability Exploited in Attacks — Securityweek · December 12, 2025
  • CVE-2025-58360: GeoServer XXE Vulnerability Analysis — Reddit · November 28, 2025

CVSS v3.1 Breakdown