A zero-day SQL injection vulnerability in GeoServer has been publicly disclosed, allowing unauthenticated users to inject SQL commands via the jsonArrayContains function. Researchers reported hundreds of exploitation…
2 articles · Updated August 14, 2026
Recent Intelligence Reports
Early exploitation attempts observed of GeoServer zero day— Fieldeffect · August 14, 2026