logo

CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks

ID: ae1c78a6-5ddf-51b6-b182-fd48607375a5

STIX ID: report--ae1c78a6-5ddf-51b6-b182-fd48607375a5

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Abinaya

...
...

CISA has added CVE-2025-58360 — an XXE vulnerability in OSGeo GeoServer's /geoserver/wms GetMap handling — to its Known Exploited Vulnerabilities catalog due to active exploitation; federal agencies must remediate under BOD 22-01 by January 1, 2026, and all users are urged to apply vendor fixes or disable affected services to prevent file disclosure, SSRF, or DoS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.