CISA orders immediate patching as GeoServer flaw faces active exploitation
csoonline.com·3d
Preview
Report Post

CISA is sounding the alarm over a critical vulnerability in GeoServer that is being actively exploited in the wild, ordering federal agencies to patch immediately.

The flaw, tracked as CVE-2025-58360, is an unauthenticated XML External Entity (XXE) vulnerability affecting GeoServer versions 2.26.1 and earlier. When exploited, the bug lets attackers retrieve arbitrary files from vulnerable servers, allowing data theft, denial-of-service attacks, or server-side request forgery (SSRF) that can expose internal systems.

GeoServer, an open-source platform for publishing and sharing geospatial data, is widely used across civilian, sci…

Similar Posts

Loading similar posts...