HispasecAugust 14, 2026🇪🇸Translated from Spanish

Critical GeoServer Vulnerability CVE-2024-36401 Actively Exploited for Unauthenticated Remote Code Execution

A critical vulnerability tracked as CVE-2024-36401 in OSGeo GeoServer is being actively exploited in the wild and can lead to unauthenticated remote code execution. The issue affects organizations and government agencies that publish geospatial data through GeoServer instances exposed to the internet.

The root cause lies in the way GeoServer and its supporting GeoTools library evaluate certain property names. In default setups, specific parameters are interpreted as XPath expressions, enabling attackers to craft malicious payloads that trigger code execution through the commons-jxpath library.

Multiple service endpoints are impacted. Attackers can target WFS requests such as GetFeature and GetPropertyValue, WMS functions including GetMap, GetFeatureInfo and GetLegendGraphic, as well as WPS Execute operations. Any internet-facing deployment publishing these endpoints is at immediate risk.

Documented incidents show a clear attack chain: initial access via the vulnerability, internal reconnaissance, lateral movement and persistence through web shells. One tool repeatedly observed is China Chopper, valued by adversaries for its simplicity and resilience after service restarts.

Official fixes have been released in GeoServer versions 2.22.6, 2.23.6, 2.24.4 and 2.25.2. Administrators should update without delay and treat any previously exposed instance as potentially compromised.

When patching cannot be completed immediately, a mitigation is to remove the gt-complex x.y.jar file from the deployment. This step reduces the attack surface but may disable required functionality and should be tested first in a staging environment.

Additional defensive measures include restricting access by IP address, enforcing VPN connections, deploying an authenticated reverse proxy and continuously monitoring logs for anomalous WFS, WMS and WPS requests. After remediation, teams must search for web shells, unexpected processes and unusual outbound connections while rotating associated credentials.

Related articles

HispasecVulnerabilities & Exploits

Critical GeoServer Vulnerability CVE-2024-36401 Actively Exploited for Unauthenticated Remote Code Execution

The CVE-2024-36401 flaw in GeoServer and its GeoTools library allows attackers to achieve remote code execution without authentication by abusing property name expressions interpreted as XPath. Active exploitation has already led to confirmed intrusions involving initial access, lateral movement, and persistence with tools such as China Chopper web shells. Multiple OGC endpoints including WFS GetFeature, WMS GetMap, and WPS Execute are affected when exposed to the internet. Patches are available in GeoServer versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2. Organizations unable to patch immediately can mitigate risk by removing the gt-complex JAR file, though this may break functionality. Additional defenses include restricting internet exposure through IP allowlisting, VPNs, and reverse proxies while monitoring logs for anomalous requests. Any previously exposed instances should be treated as potentially compromised, with full incident response including credential rotation and host forensics recommended.

BoletimSecVulnerabilities & Exploits

Fortinet Patches Critical Authentication Bypass in FortiWeb Allowing Login with Random Credentials

Fortinet has released security updates addressing multiple vulnerabilities across FortiWeb, FortiManager, and FortiClient products. The most severe issue, tracked as CVE-2026-26035, affects FortiWeb and carries a CVSS score of 8.8. The flaw occurs when administrative accounts configured with remote RADIUS authentication use the wildcard option, which is disabled by default. Under these conditions, an unauthenticated remote attacker can gain administrative access to the web application firewall by supplying arbitrary usernames and passwords. Successful exploitation grants full control over the FortiWeb instance, potentially compromising web application security. The vulnerability impacts FortiWeb versions 8.0, 7.6, 7.4, 7.2, and 7.0, with fixes available in versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. No active exploitation of the authentication bypass flaws has been observed so far, but the risk of remote administrative access makes immediate patching essential for exposed appliances.

BoletimSecVulnerabilities & Exploits

Microsoft Patches Seven Exchange Server Vulnerabilities Including Critical Remote Code Execution Flaw

Microsoft has addressed seven vulnerabilities in Exchange Server that enable remote code execution, privilege escalation, denial of service, content spoofing, and security feature bypass. The most severe issue, CVE-2026-62913, carries a CVSS score of 8.8 and involves a heap buffer overflow that can be exploited remotely by a low-privileged attacker without any user interaction. Successful exploitation grants code execution on the server, facilitating email theft, persistence mechanisms, lateral movement, and ransomware deployment. CVE-2026-62911, demonstrated at Pwn2Own Berlin with a CVSS score of 8.0, allows authentication bypass through capture and replay of credentials. Additional fixes cover SSRF-based privilege escalation, remote deserialization crashes, content spoofing, and authorization bypasses. Patches are available for Exchange Server Subscription Edition, while 2016 and 2019 versions receive updates only through the Extended Security Update program.

Security NEXTVulnerabilities & Exploits

Cisco Pre-Announces Security Advisories for Nine Product Families on August 19

Cisco Systems has issued an advance notice that it will publish security advisories for multiple products on August 19, 2026. The company released the pre-notification on August 12, confirming that nine distinct product groups will receive updates addressing security issues. No specific CVE identifiers, vulnerability descriptions, severity ratings, or affected versions were disclosed in the initial announcement. Cisco strongly recommends that customers apply the forthcoming fixes once they become available. The affected product families span collaboration, networking, contact center, and security platforms. Organizations using any of the listed solutions are advised to prepare for the upcoming patches and monitor Cisco’s official channels for detailed advisories.