logo

CISA warns critical Geoserver GeoTools RCE flaw is exploited in attacks

ID: ba57bd4b-d410-59bf-aa5e-3d3f9171b4f9

STIX ID: report--ba57bd4b-d410-59bf-aa5e-3d3f9171b4f9

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-07-16

Date Updated: 2026-07-19

Author: Lawrence Abrams

...
...

CISA warns that CVE-2024-36401, a critical (CVSS 9.8) remote code execution flaw in GeoServer's GeoTools plugin that improperly evaluates property names as XPath expressions, is being actively exploited; proof-of-concept exploits were published, Shadowserver observed exploitation beginning July 9, and CISA added the CVE to its Known Exploited Vulnerabilities catalog requiring federal patching. GeoServer maintainers released fixes (2.23.6, 2.24.4, 2.25.2) and recommend immediate upgrades or mitigations and thorough review of systems and logs, noting around 16,462 exposed GeoServer instances online.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.