42
55
30
55
30
55
GeoServer Zero-Day Is Already Being Probed. That’s the Problem
Unpatched GeoServer zero-day enabling SQL injection and possible RCE is being actively probed across exposed systems.
A zero-day in GeoServer's jsonArrayContains functionality allows unauthorized SQL injection and, in some configurations, remote code execution. Disclosed on August 12, 2026 without a CVE ID, it drew hundreds of exploitation probes from watchTowr within hours. No patch is available yet; GeoServer was previously mass-exploited via CVE-2024-36401.
82
55
55
57
30
55
60
60
30
30
30
30
60
57
55
60
30
30
57
30
60
30
57
30
42
60
60
30
30
42
30
60
42
30