GeoServer exploitation, federal breach, and monetization activity
Case score 68
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 68
- Main story score
- 61
- Related evidence lift
- +7 / 20
- Contributing updates
- 3
- Context updates
- 0
- Vulnerability Anchors the case in active exploitation of CVE-2024-36401 in GeoServer and the resulting federal breach story. main
- Campaign Shows separate CVE-2024-36401 abuse against internet-exposed GeoServer instances for low-noise monetization. contributes
- Incident Provides confirmed fallout from CVE-2024-36401 exploitation, including lateral movement and web shell use. contributes
- Vulnerability Adds later GeoServer exploitation pressure through CVE-2025-58360 and its KEV listing. contributes
Overview
Latest development Open development history CVE-2025-58360 exploit exists in the wild A Canadian Centre for Cyber Security bulletin said an exploit for OSGeo GeoServer CVE-2025-58360 exists in the wild, indicating active exploitation against vulnerable GeoServer deployments.
-
CISA adds GeoServer CVE-2025-58360 to KEV
On December 12, 2025, CISA added OSGeo GeoServer CVE-2025-58360 to the Known Exploited Vulnerabilities catalog after evidence of active exploitation in the wild. The unauthenticated XML External Entity flaw affects all versions prior to and including 2.25.5 and 2.26.0 through 2.26.1, with fixed releases available in 2.25.6, 2.26.2, 2.27.0, 2.28.0, and 2.28.1; successful exploitation can expose arbitrary files, enable SSRF, or trigger DoS, and FCEB agencies were advised to apply required fixes by January 1, 2026.
-
CVE-2024-36401 attacks observed
Threat monitoring observed CVE-2024-36401 attacks against exposed GeoServer servers starting on July 9, 2024, while OSINT search tracking showed more than 16,000 GeoServer servers exposed online.
-
CVE-2024-36401 attacks begin and exposure is broad
Threat monitoring saw CVE-2024-36401 attacks starting on July 9, 2024, while ZoomEye tracked more than 16,000 GeoServer servers exposed online.
-
GeoServer CVE-2024-36401 bandwidth-sharing campaign
The campaign began with **probing of internet-exposed GeoServer instances** and exploitation of **CVE-2024-36401**. From there, attackers started dropping **customized executables** from controlled infrastructure to monetize compromised systems.