CISA orders feds to patch actively exploited Geoserver flaw
ID: c2c4750c-e8c4-5815-81b6-497b8dc22c07
STIX ID: report--c2c4750c-e8c4-5815-81b6-497b8dc22c07
Feed Name: Bleeping Computer
Threat Score
CISA warns of an actively exploited unauthenticated XML External Entity (XXE) vulnerability (CVE-2025-58360) in GeoServer ≤2.26.1 that can retrieve arbitrary files and enable SSRF; the flaw was added to CISA's KEV catalog with a federal patching deadline and thousands of exposed instances have been identified by scanners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
