THREATOPS
THREAT OPSThreat News › GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

lowthehackernewsPublished 2026-08-13

A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr.

The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched.

It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @

Original source: https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html