As cited
Copy frozen at (site build).
vulnerabilities
GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
A zero-day SQL injection vulnerability in GeoServer is under active exploitation and can lead to remote code execution. The flaw, disclosed on August 12, 2026, remains unpatched and has not yet received a CVE identifier.
Why it matters: Organizations running GeoServer are at immediate risk of code execution; patching information and defensive measures should be evaluated as soon as the vendor releases guidance.
- Source published
- First seen by Cybersecurity Tracker