GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public
18 de Agosto de 2026, 01:35
A GeoServer unauthenticated SQL injection (CVSS 9.8) is exploited in the wild. A public PoC reaches RCE. Patch GeoServer now.
Related Posts:
- CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1)
- PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF
- CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups
The post GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public appeared first on Daily CyberSecurity.