Find notable cyber news and cases, enriched with sources, timelines, and signals.

GeoNetwork patch release for unauthenticated RCE chain (4.4.12, 4.2.17)

Security Patch Release
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

GeoNetwork shipped 4.4.12 and 4.2.17 to close a vulnerability chain that could lead to unauthenticated remote code execution in exposed deployments. The fix applies to 4.4.x through 4.4.11 and 4.2.x through 4.2.16, making the release relevant for government and agency geoportals and other public-facing catalogs. Administrators were told to upgrade to 4.4.12 or 4.2.17 as soon as possible.

Related Happenings

OpenWrt security patch release for CVE-2026-53921

Security Patch Release
H score37 First: 28.07.2026 15:56 Last: 28.07.2026 15:56 Sources 1

About this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...

Timeline

  1. 31.08.2026 03:00 1 articles · 2d ago

    GeoNetwork discloses chained formatter-upload and XSLT flaws

    Initial Disclosure

    GeoNetwork publishes vulnerability details for a chain built from a missing authorization check on the formatter upload endpoint and an unsafe Saxon XSLT configuration that can run java.lang.Runtime.exec() or java.lang.ProcessBuilder as the GeoNetwork process user. The affected release range is 4.4.x through 4.4.11 and 4.2.x through 4.2.16.

    Show sources
  2. 08.07.2026 03:00 2 articles · 1mo ago

    GeoNetwork releases 4.4.12 and 4.2.17 to close unauthenticated RCE chain

    Mitigation Patch Update

    GeoNetwork ships versions 4.4.12 and 4.2.17 to fix CVE-2026-63219 and CVE-2026-58400, closing a chain that lets an unauthenticated attacker upload a formatter and trigger code execution through the Saxon XSLT processor. Administrators are told to upgrade to 4.4.12 or 4.2.17 immediately.

    Show sources