logo

Rondo Meets Geoserver, (Wed, Jul 22nd)

ID: edb2565a-fa61-5058-84c1-c1cf6688a1b7

STIX ID: report--edb2565a-fa61-5058-84c1-c1cf6688a1b7

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2026-07-22

Date Updated: 2026-08-06

...
...

A GeoServer XPath expression evaluation vulnerability (CVE-2024-36401) was actively exploited: an observed GET request used a crafted GetPropertyValue valueReference to exec a shell command that base64-decoded to a wget/curl one-liner fetching and executing a Rondo botnet script from 45.153.34.153. The report includes the original encoded request, the decoded command, and notes that Rondo has targeted GeoServer previously; evidence is from server logs showing the attack and the resulting (possibly removed) payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.