⤷ Title: CVE-2024-36401: Critical Vulnerability in GeoServer Allows RCE by Unauthenticated Users
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Tue, 31 Dec 2024 19:36:27 GMT
════════════════════════
⌗ Tags: #geoserver_rce_exploit #cve_2024_36401 #geoserver_security_patch #rce #unauthenticated_rce
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Tue, 31 Dec 2024 19:36:27 GMT
════════════════════════
⌗ Tags: #geoserver_rce_exploit #cve_2024_36401 #geoserver_security_patch #rce #unauthenticated_rce
Medium
CVE-2024-36401: Critical Vulnerability in GeoServer Allows RCE by Unauthenticated Users
[Write-up] CVE-2024-36401: Exploiting GeoServer RCE Vulnerability and How to Protect Your System.
⤷ Title: Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
Daily CyberSecurity
Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
GeoServer's RCE flaw (CVE-2024-36401) is actively exploited to deploy NetCat reverse shells and XMRig CoinMiners on Windows/Linux, hijacking resources.
⤷ Title: CVE-2024-36401 Exploited in Stealthy Bandwidth-Monetization Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 Aug 2025 00:28:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #CVE_2024_36401 #Cybercrime #cybersecurity #GeoServer #passive income #rce #Remote Code Execution #Unit 42 #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 Aug 2025 00:28:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #CVE_2024_36401 #Cybercrime #cybersecurity #GeoServer #passive income #rce #Remote Code Execution #Unit 42 #Vulnerability
Daily CyberSecurity
CVE-2024-36401 Exploited in Stealthy Bandwidth-Monetization Campaign
A new report reveals a stealthy attack on GeoServer using a critical RCE flaw. Instead of ransomware, attackers are hijacking servers to earn passive income.
⤷ Title: High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:22:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #File Exfiltration #GeoServer #ssrf #unauthenticated #WMS GetMap #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:22:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #File Exfiltration #GeoServer #ssrf #unauthenticated #WMS GetMap #XML External Entity #xxe
Daily CyberSecurity
High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
GeoServer patched a High-severity XXE flaw (CVE-2025-58360, CVSS 8.2) in its WMS GetMap operation. The flaw allows unauthenticated remote attackers to read arbitrary files and perform SSRF. Update to v2.27.0.
⤷ Title: CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:00:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58360 #Data Theft #GeoServer #ssrf #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:00:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58360 #Data Theft #GeoServer #ssrf #XML External Entity #xxe
Daily CyberSecurity
CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
CISA added a critical XXE flaw (CVE-2025-58360) in OSGeo GeoServer to the KEV Catalog. The actively exploited bug allows attackers to read arbitrary files and perform SSRF on internal networks. Patch immediately.