Frequency
3
occurrences
First Seen
November 28, 2025
Last Seen
September 2, 2026
Related Threat Clusters
-
GeoNetwork Vulnerabilities Enable Unauthenticated RCE Attacks
GeoNetwork, an open-source geospatial metadata catalog, has two vulnerabilities that can be exploited to achieve unauthenticated remote code execution (RCE). The flaws, CVE-2026-63219 and CVE-2026-58400, allow attackers…
2 articles · Updated September 2, 2026 -
GeoServer XXE Vulnerability Exploited in Cyber Attacks
A recently discovered vulnerability in GeoServer, identified as CVE-2025-58360, allows attackers to exploit insufficiently sanitized user input to define external entities within XML requests. This flaw has been…
3 articles · Updated December 12, 2025
Recent Intelligence Reports
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends — Thehackernews · September 2, 2026
- Recent GeoServer Vulnerability Exploited in Attacks — Securityweek · December 12, 2025
- CVE-2025-58360: GeoServer XXE Vulnerability Analysis — Reddit · November 28, 2025