A critical zero-day vulnerability in GeoServer, a widely used open-source platform for geospatial data processing and sharing, has been exploited by hackers just hours after its public disclosure. According to attack surface management firm WatchTowr, threat actors have begun probing vulnerable systems using this unpatched security defect, which can be exploited to execute remote code on affected servers.
The vulnerability affects GeoServer’s jsonArrayContains function, a filter expression used for querying JSON array fields in PostGIS and Oracle JDBC data stores. When user-supplied arguments are improperly sanitized before being encoded into database queries, it creates an opportunity for SQL injection attacks, potentially leading to remote code execution (RCE). WatchTowr reports observing hundreds of exploitation attempts originating from a small number of source IP addresses since the vulnerability’s public disclosure.
GeoServer is used across various industries, including government, agriculture, telecoms, and transit. Its widespread adoption makes it an attractive target for hackers seeking to exploit vulnerabilities at scale. In fact, GeoServer has been listed in CISA’s Known Exploited Vulnerabilities catalog, indicating a history of being targeted by attackers.
While no follow-up activity has been observed so far, WatchTowr cautions that organizations running GeoServer should take this vulnerability seriously and consider identifying exposed instances, restricting public access, and monitoring for a vendor fix. With the rapid pace at which hackers move once a vulnerability enters the public domain, it’s essential for affected parties to act swiftly.
The rate at which threat actors exploit newly disclosed vulnerabilities is concerning. This case serves as a reminder that organizations must prioritize patch management, stay informed about publicly disclosed security issues, and remain vigilant in their monitoring efforts. By doing so, they can minimize the risk of falling victim to exploitation attempts.
Given the severity of this vulnerability and its potential impact on various industries, it’s crucial for GeoServer users to take immediate action and consider implementing additional security measures until a patch is released. As we’ve seen time and again, prompt attention to such vulnerabilities can prevent significant damage and minimize downtime.
Source: SecurityWeek — 2026-08-14