GeoServer is a technology platform tracked across 4 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed November 28, 2025; most recent activity June 25, 2026.
GeoServer is an open-source geospatial server platform that enables sharing and editing of geospatial data, typically serving via standards like WMS and WFS and running on Java. Recent reporting identifies a critical XML External Entity (XXE) vulnerability in GeoServer (CVE-2025-58360) that is being actively exploited, elevating risk for exposed GIS services and infrastructure.
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to…
CISA has flagged critical vulnerabilities in DigiEver network video recorders and GeoServer, both of which are actively being exploited. The vulnerabilities have been added to the Known Exploited Vulnerabilities (KEV)…
A recently discovered vulnerability in GeoServer, identified as CVE-2025-58360, allows attackers to exploit insufficiently sanitized user input to define external entities within XML requests. This flaw has been…