HispasecAugust 14, 2026🇪🇸Translated from Spanish

Critical GeoServer Vulnerability CVE-2024-36401 Actively Exploited for Unauthenticated Remote Code Execution

A critical vulnerability tracked as CVE-2024-36401 in GeoServer is being actively exploited in the wild, enabling unauthenticated remote code execution that can result in full server takeover.

The issue stems from the way GeoServer and its underlying GeoTools library evaluate certain property names. In default configurations these parameters can be processed as XPath expressions, allowing malicious payloads to trigger code execution via the commons-jxpath library.

Attackers can abuse multiple OGC services to reach the vulnerable code path. Affected request types include WFS operations such as GetFeature and GetPropertyValue, WMS calls including GetMap, GetFeatureInfo and GetLegendGraphic, as well as WPS Execute requests. Any internet-facing instance publishing these endpoints is at immediate risk.

Observed attack chains follow a familiar pattern: initial compromise via the CVE-2024-36401 exploit, network reconnaissance, lateral movement, and persistence through web shells. One frequently deployed tool is the China Chopper web shell, valued by attackers for its simplicity and resilience after service restarts.

Official fixes are already available. Patched releases include GeoServer 2.22.6, 2.23.6, 2.24.4 and 2.25.2. Administrators should update without delay and assume any previously exposed, unpatched instance may be compromised.

When patching cannot be completed immediately, a temporary mitigation involves removing the gt-complex JAR file from the deployment. This step reduces the attack surface but may disable required functionality or prevent service startup; testing in a staging environment is strongly advised.

Additional hardening measures include limiting access by IP address, enforcing VPN connectivity, deploying an authenticating reverse proxy, and continuously reviewing GeoServer and web-server logs for suspicious WFS, WMS and WPS requests containing unusual filter parameters.

Related articles

Security NEXTVulnerabilities & Exploits

Critical Vulnerabilities Patched in VMware Workstation and Fusion Allowing Host Code Execution

Broadcom has disclosed two vulnerabilities in VMware Workstation and VMware Fusion rated as critical and important respectively. CVE-2026-59346 is an integer overflow flaw in the VMXNET3 virtual network adapter that can be exploited by a local administrator inside a virtual machine to execute arbitrary code on the host system, carrying a CVSS v3.1 base score of 9.3. CVE-2026-59347 is a stack-based buffer overflow in the HGFS file system that permits code execution on the host as the VMX process with a CVSS score of 8.1. Both issues were privately reported and affect users who run virtual machines with local administrative privileges. The flaws have been addressed in VMware Workstation 26H1u1 and VMware Fusion 26H1u1, and Broadcom urges immediate updates via advisory VMSA-2026-0007.

Security NEXTVulnerabilities & Exploits

Google Chrome Patches 12 Vulnerabilities Including Actively Exploited V8 Zero-Day

Google has released security updates for Chrome addressing 12 vulnerabilities across Windows, macOS, and Linux platforms. The updates include versions 152.0.7977.83 and 152.0.7977.82 for Windows and macOS, and 152.0.7977.82 for Linux. No critical-rated flaws were fixed in this batch, but ten issues carry a high severity rating. The most notable is CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine that was reported on August 4 and is already being exploited in the wild. Additional high-severity fixes cover a race condition in V8 (CVE-2026-85045), a use-after-free in Compositing (CVE-2026-85048), and another type confusion issue (CVE-2026-85051). This marks the second Chrome security update in three days.

HabrVulnerabilities & Exploits

Bcrypt Password Hashing Silently Ignores Characters Beyond 72 Bytes, Breaking Verification Expectations

The bcrypt algorithm, widely used for password hashing in PHP and Python applications, processes only the first 72 bytes of any input password. Additional characters are ignored without error or warning during both hashing with password_hash and verification with password_verify. This behavior stems from the fixed 72-byte P-table size in the underlying Blowfish cipher as defined in the 1999 specification. Long passphrases, especially those using multibyte UTF-8 characters like Cyrillic or emojis, can result in completely different strings producing identical hashes. The limitation creates risks during password manager usage, system migrations, and scenarios involving shared prefixes. Modern libraries such as Python's bcrypt 4.x now explicitly reject passwords exceeding 72 bytes, while older implementations continue silent truncation. Recommended fixes include enforcing byte-length validation or pre-hashing with SHA-256 before bcrypt.

Security NEXTVulnerabilities & Exploits

CISA Adds Seven Exploited Vulnerabilities in SonicWall, JFrog and Kestra to KEV Catalog

The US Cybersecurity and Infrastructure Security Agency has added seven known exploited vulnerabilities affecting SonicWall SMA1000, JFrog Artifactory and Kestra OSS products to its KEV catalog. Five of the flaws carry a three-day remediation deadline for federal agencies. Two issues in SonicWall SMA1000 enable unauthenticated server-side request forgery and authenticated OS command execution. A critical authentication bypass in JFrog Artifactory allows remote attackers to obtain administrative privileges. Kestra OSS is affected by an OS command injection vulnerability that can lead to full system compromise. CISA urges immediate patching and incident response actions.