CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Unpatched GeoServer Zero-Day Actively Exploited, Could Lead to Remote Code Execution

August 13, 2026

A newly disclosed zero-day vulnerability in GeoServer is being actively exploited in the wild, according to threat intelligence firm watchTowr. The flaw, an unauthorized SQL injection vulnerability in the open-source mapping server, can lead to remote code execution (RCE) under certain configurations. As of now, no CVE identifier has been assigned, and no patch is available.

The vulnerability was first disclosed on August 12, 2026, by security researcher @q1uf3ng on X (formerly Twitter). The researcher stated that the SQL injection in GeoServer’s jsonArrayContains function could naturally lead to RCE, particularly when the underlying database is SAP HANA (referred to as ‘sa database’).

watchTowr reported observing exploitation attempts within hours of the public disclosure, with hundreds of attempts originating from a small pool of IP addresses. Jake Knott, principal security researcher at watchTowr, noted that attackers are currently probing for vulnerable systems, triggering errors but not yet proceeding further. However, he warned that this is unlikely to remain the case for long, given GeoServer’s track record of being targeted at scale, with multiple vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog.

In the absence of a patch, organizations running GeoServer are advised to identify exposed instances, restrict public access, and monitor for vendor updates. This incident follows a similar pattern to CVE-2024-36401, a critical flaw in GeoServer GeoTools (CVSS 9.8) that was actively exploited in 2024 to turn compromised devices into DDoS and cryptocurrency mining botnets.

This is a developing story, and more details are expected as the situation evolves.

CVEs: CVE-2024-36401

Companies: watchTowr

Products: GeoServer, GeoServer GeoTools