logo

CISA orders feds to patch actively exploited Geoserver flaw

ID: c2c4750c-e8c4-5815-81b6-497b8dc22c07

STIX ID: report--c2c4750c-e8c4-5815-81b6-497b8dc22c07

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-12-12

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA warns of an actively exploited unauthenticated XML External Entity (XXE) vulnerability (CVE-2025-58360) in GeoServer ≤2.26.1 that can retrieve arbitrary files and enable SSRF; the flaw was added to CISA's KEV catalog with a federal patching deadline and thousands of exposed instances have been identified by scanners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.