GeoServer GeoTools jsonArrayContains unauthorized SQL injection actively exploited SQL injection flaw
Vulnerability
Summary
Hide ▲
Show ▼
GeoServer is facing a zero-day SQL injection flaw in the GeoTools gt-jdbc-postgis path, with active exploitation attempts and remote code execution risk under some configurations. The issue was disclosed on August 12, 2026 and was unpatched at disclosure. GeoServer later released 3.0.1, 2.28.5, and 2.27.6 to fix the vulnerability.
Related Happenings
CISA orders federal patching of Oracle WebLogic CVE-2024-21182
Public Sector Action
H score53
First: 02.06.2026 15:40
Last: 02.06.2026 15:40
Sources 1
About this happening:
CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...
CISA orders federal patching of Oracle WebLogic CVE-2024-21182
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...
CISA orders FCEB patching for CVE-2026-9082
Public Sector Action
H score70
First: 26.05.2026 11:46
Last: 26.05.2026 11:46
Sources 1
About this happening:
CISA added CVE-2026-9082 to the KEV Catalog and ordered FCEB agencies to patch Drupal by May 27, turning an actively exploited flaw into a mandatory federa...
CISA orders FCEB patching for CVE-2026-9082
Public Sector ActionAbout this happening: CISA added CVE-2026-9082 to the KEV Catalog and ordered FCEB agencies to patch Drupal by May 27, turning an actively exploited flaw into a mandatory federa...
CISA orders FCEB patching for MongoBleed
Public Sector Action
H score79
First: 30.12.2025 16:40
Last: 30.12.2025 16:40
Sources 1
About this happening:
CISA ordered FCEB agencies to patch CVE-2025-14847 after confirming it was actively exploited in attacks, creating an urgent remediation requirement for federal sy...
CISA orders FCEB patching for MongoBleed
Public Sector ActionAbout this happening: CISA ordered FCEB agencies to patch CVE-2025-14847 after confirming it was actively exploited in attacks, creating an urgent remediation requirement for federal sy...
Timeline
-
13.08.2026 21:45 2 articles · 3d ago
GeoServer GeoTools jsonArrayContains unauthorized SQL injection actively exploited SQL injection flaw
Initial DisclosureOn August 12, 2026, researchers disclosed a GeoServer jsonArrayContains SQL injection flaw with RCE potential, and watchTowr observed exploitation attempts within hours. The issue was unpatched at disclosure, leaving exposed systems at immediate risk.
Show sources
- GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE — thehackernews.com — 13.08.2026 21:45
- GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE — thehackernews.com — 13.08.2026 21:45