Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Campaign Incident

GeoServer exploitation, federal breach, and monetization activity

Updated 12.12.2025 07:01
Case score 68
Members 4 First seen 23.08.2025 10:38 Latest activity 12.12.2025 07:01

Overview

**CVE-2024-36401** in **GeoServer** moved from patch release to active exploitation, with CISA later tying an unpatched GeoServer instance to a federal breach and a separate campaign using the same flaw to monetize exposed servers. The federal intrusion stayed active for about three weeks before EDR alerted, and the attackers expanded from GeoServer into additional internal systems. A later **GeoServer CVE-2025-58360** KEV listing shows the product remains under sustained remediation pressure. Available evidence does not show that the newer XXE flaw was used in the federal breach, and exposure across GeoServer deployments is not quantified.
Latest development Open development history 4 earlier developments CVE-2025-58360 exploit exists in the wild A Canadian Centre for Cyber Security bulletin said an exploit for OSGeo GeoServer CVE-2025-58360 exists in the wild, indicating active exploitation against vulnerable GeoServer deployments.
  1. Earlier development

    CISA adds GeoServer CVE-2025-58360 to KEV

    On December 12, 2025, CISA added OSGeo GeoServer CVE-2025-58360 to the Known Exploited Vulnerabilities catalog after evidence of active exploitation in the wild. The unauthenticated XML External Entity flaw affects all versions prior to and including 2.25.5 and 2.26.0 through 2.26.1, with fixed releases available in 2.25.6, 2.26.2, 2.27.0, 2.28.0, and 2.28.1; successful exploitation can expose arbitrary files, enable SSRF, or trigger DoS, and FCEB agencies were advised to apply required fixes by January 1, 2026.

  2. Earlier development

    CVE-2024-36401 attacks observed

    Threat monitoring observed CVE-2024-36401 attacks against exposed GeoServer servers starting on July 9, 2024, while OSINT search tracking showed more than 16,000 GeoServer servers exposed online.

  3. Earlier development

    CVE-2024-36401 attacks begin and exposure is broad

    Threat monitoring saw CVE-2024-36401 attacks starting on July 9, 2024, while ZoomEye tracked more than 16,000 GeoServer servers exposed online.

  4. Earlier development

    GeoServer CVE-2024-36401 bandwidth-sharing campaign

    The campaign began with **probing of internet-exposed GeoServer instances** and exploitation of **CVE-2024-36401**. From there, attackers started dropping **customized executables** from controlled infrastructure to monetize compromised systems.

Signals

Exploitation
Affected impact
CVEs/products
Geographic context
Remediation
Status
Threat context
Data exposure

Threat actor context

2 listed

Malware & tooling context

3 families · 2 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability GeoServer critical RCE vulnerability (CVE-2024-36401)
Updated 23.09.2025 18:07 Lead Contribution 61
Exploitation Active Exploitation Exploit Public Exploit CVSS 9.8 Critical Data Status Exposed/Unsecured 1 more in details
All signals
Exploitation Active Exploitation Exploit Public Exploit CVSS 9.8 Critical Data Status Exposed/Unsecured Patch Patch Available

**CVE-2024-36401** is a critical **GeoServer** remote code execution vulnerability that was patched on **June 18, 2024** and later **actively exploited** against exposed servers. In a later **CISA** disclosure, attackers breached a **large unnamed FCEB agency** by abusing the flaw in **GeoServer**, then used **Burp Suite** for scanning, accessed a second GeoServer, **moved laterally to two other servers**, and dropped web shells including **China Chopper**. The agency’s delayed remediation, weak incident response, and limited logging left the activity undetected for **three weeks** and complicated containment.

Campaign GeoServer CVE-2024-36401 bandwidth-sharing campaign
Updated 23.08.2025 10:38 Scoring Support Contribution 2
Campaign Active

An active **GeoServer** exploitation campaign is using **CVE-2024-36401** to turn exposed servers into infrastructure for **bandwidth sharing** and other passive-income abuse. The activity has been seen against **internet-facing GeoServer instances** since **early March 2025**, increasing the risk that unpatched deployments are being quietly repurposed. The campaign matters because the payloads are delivered from **adversary-controlled servers** and are designed to stay low-profile while monetizing compromised systems.

Vulnerability OSGeo GeoServer actively exploited XXE flaw (CVE-2025-58360)
Updated 12.12.2025 07:01 Scoring Support Contribution 2
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**CISA** added **CVE-2025-58360** in **OSGeo GeoServer** to the **KEV catalog** after evidence of **active exploitation** in the wild. The flaw is an **unauthenticated XXE** issue affecting **all versions through 2.25.5** and **2.26.0 through 2.26.1**, with fixes now available in later releases. Successful abuse could enable **arbitrary file access**, **SSRF**, or **DoS** against exposed GeoServer instances.

Incident U.S. federal civilian executive branch agency hit by network compromise
Updated 23.09.2025 18:07 Scoring Support Contribution 2
Extortion None Incident Disclosed Patch Patch Available

An **unnamed U.S. federal civilian executive branch agency** was breached after attackers exploited **CVE-2024-36401** in **GeoServer**, then used the foothold to move laterally to a **web server** and **SQL server**. **CISA** said the activity remained undetected for **three weeks** and that the agency's weak incident response, logging, and patching slowed containment. The attackers used **Burp Suite** for scanning, **China Chopper** web shells, **brute force** password attacks, and **Stowaway** for C2 traffic.