CYBERSECURITYTRACKER
TRACKING
Permanent story citation

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4523

As cited

Copy frozen at (site build).

vulnerabilities

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

A zero-day SQL injection vulnerability in GeoServer is under active exploitation and can lead to remote code execution. The flaw, disclosed on August 12, 2026, remains unpatched and has not yet received a CVE identifier.

Why it matters: Organizations running GeoServer are at immediate risk of code execution; patching information and defensive measures should be evaluated as soon as the vendor releases guidance.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary