Critical GeoServer Vulnerability CVE-2024-36401 Actively Exploited for Unauthenticated Remote Code Execution
A critical vulnerability tracked as CVE-2024-36401 in GeoServer is being actively exploited in the wild, enabling unauthenticated remote code execution that can result in full server takeover.
The issue stems from the way GeoServer and its underlying GeoTools library evaluate certain property names. In default configurations these parameters can be processed as XPath expressions, allowing malicious payloads to trigger code execution via the commons-jxpath library.
Attackers can abuse multiple OGC services to reach the vulnerable code path. Affected request types include WFS operations such as GetFeature and GetPropertyValue, WMS calls including GetMap, GetFeatureInfo and GetLegendGraphic, as well as WPS Execute requests. Any internet-facing instance publishing these endpoints is at immediate risk.
Observed attack chains follow a familiar pattern: initial compromise via the CVE-2024-36401 exploit, network reconnaissance, lateral movement, and persistence through web shells. One frequently deployed tool is the China Chopper web shell, valued by attackers for its simplicity and resilience after service restarts.
Official fixes are already available. Patched releases include GeoServer 2.22.6, 2.23.6, 2.24.4 and 2.25.2. Administrators should update without delay and assume any previously exposed, unpatched instance may be compromised.
When patching cannot be completed immediately, a temporary mitigation involves removing the gt-complex JAR file from the deployment. This step reduces the attack surface but may disable required functionality or prevent service startup; testing in a staging environment is strongly advised.
Additional hardening measures include limiting access by IP address, enforcing VPN connectivity, deploying an authenticating reverse proxy, and continuously reviewing GeoServer and web-server logs for suspicious WFS, WMS and WPS requests containing unusual filter parameters.
Related articles
Critical GeoServer Vulnerability CVE-2024-36401 Actively Exploited for Unauthenticated Remote Code Execution
The vulnerability CVE-2024-36401 in GeoServer is already being exploited in real-world attacks and enables remote code execution without authentication. The flaw stems from how GeoServer and its GeoTools library interpret certain property names, allowing malicious XPath expressions via commons-jxpath in default configurations. Attackers can abuse multiple OGC endpoints including WFS GetFeature and GetPropertyValue, WMS GetMap, GetFeatureInfo and GetLegendGraphic, plus WPS Execute to gain initial access. Observed intrusions follow a familiar pattern of reconnaissance, lateral movement and persistence with web shells such as China Chopper. Patches are available in GeoServer 2.22.6, 2.23.6, 2.24.4 and 2.25.2, while a temporary mitigation involves removing the gt-complex jar file. Organizations are urged to apply updates immediately, restrict internet exposure and hunt for indicators of compromise in logs and on hosts.
Fortinet Patches Critical Authentication Bypass in FortiWeb Allowing Login with Random Credentials
Fortinet has released security updates addressing multiple vulnerabilities across FortiWeb, FortiManager, and FortiClient products. The most severe issue, tracked as CVE-2026-26035, affects FortiWeb and carries a CVSS score of 8.8. The flaw occurs when administrative accounts configured with remote RADIUS authentication use the wildcard option, which is disabled by default. Under these conditions, an unauthenticated remote attacker can gain administrative access to the web application firewall by supplying arbitrary usernames and passwords. Successful exploitation grants full control over the FortiWeb instance, potentially compromising web application security. The vulnerability impacts FortiWeb versions 8.0, 7.6, 7.4, 7.2, and 7.0, with fixes available in versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. No active exploitation of the authentication bypass flaws has been observed so far, but the risk of remote administrative access makes immediate patching essential for exposed appliances.
Microsoft Patches Seven Exchange Server Vulnerabilities Including Critical Remote Code Execution Flaw
Microsoft has addressed seven vulnerabilities in Exchange Server that enable remote code execution, privilege escalation, denial of service, content spoofing, and security feature bypass. The most severe issue, CVE-2026-62913, carries a CVSS score of 8.8 and involves a heap buffer overflow that can be exploited remotely by a low-privileged attacker without any user interaction. Successful exploitation grants code execution on the server, facilitating email theft, persistence mechanisms, lateral movement, and ransomware deployment. CVE-2026-62911, demonstrated at Pwn2Own Berlin with a CVSS score of 8.0, allows authentication bypass through capture and replay of credentials. Additional fixes cover SSRF-based privilege escalation, remote deserialization crashes, content spoofing, and authorization bypasses. Patches are available for Exchange Server Subscription Edition, while 2016 and 2019 versions receive updates only through the Extended Security Update program.
Cisco Pre-Announces Security Advisories for Nine Product Families on August 19
Cisco Systems has issued an advance notice that it will publish security advisories for multiple products on August 19, 2026. The company released the pre-notification on August 12, confirming that nine distinct product groups will receive updates addressing security issues. No specific CVE identifiers, vulnerability descriptions, severity ratings, or affected versions were disclosed in the initial announcement. Cisco strongly recommends that customers apply the forthcoming fixes once they become available. The affected product families span collaboration, networking, contact center, and security platforms. Organizations using any of the listed solutions are advised to prepare for the upcoming patches and monitor Cisco’s official channels for detailed advisories.