Hackers are already probing and exploiting a newly disclosed flaw in GeoServer, a widely used open source platform for sharing geospatial data. The issue is an unpatched SQL injection vulnerability in GeoServer's jsonArrayContains function that affects PostGIS and Oracle JDBC data stores and may allow remote code execution under certain configurations. WatchTowr says it saw hundreds of exploitation attempts within hours of public disclosure.
Why it matters: Organizations using GeoServer may be exposed right now, with no vendor patch yet available. Admins should urgently identify internet-facing GeoServer instances, restrict public access where possible, and monitor for signs of exploitation and a future fix.
Ionut Arghire
2026.08.14
100% relevant
This article appears to be the first tracked report establishing the underlying event: public disclosure and immediate in-the-wild exploitation of an unpatched GeoServer SQL injection zero-day with potential remote code execution.
← Back to all stories