Find notable cyber news and cases, enriched with sources, timelines, and signals.

GeoNetwork unauthenticated RCE chain (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

GeoNetwork's 4.4.x through 4.4.11 and 4.2.x through 4.2.16 releases now have a chained unauthenticated RCE flaw that can affect government geoportal backends. The issue combines CVE-2026-63219 and CVE-2026-58400 to let an anonymous attacker upload a malicious formatter and trigger command execution through Saxon XSLT. The project shipped fixes in 4.4.12 and 4.2.17 and urged users to upgrade quickly. No public exploitation in the wild was reported at disclosure.

Related Happenings

CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551

Public Sector Action
H score53 First: 04.02.2026 07:50 Last: 04.02.2026 07:50 Sources 1

About this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...

Timeline

  1. 02.09.2026 03:00 1 articles · 11h ago

    GeoNetwork ships fixes for chained unauthenticated RCE flaws

    Mitigation Patch Update

    GeoNetwork released versions 4.4.12 and 4.2.17 to fix CVE-2026-63219, a missing authorization check on the formatter upload endpoint, and CVE-2026-58400, an unsafe Saxon XSLT configuration that can be chained with the upload flaw to let an unauthenticated attacker upload a malicious formatter and trigger operating-system command execution through a public record request.

    Show sources
  2. 02.09.2026 03:00 2 articles · 11h ago

    GeoNetwork publishes details on CVE-2026-63219 and CVE-2026-58400

    Initial Disclosure

    GeoNetwork published details for the chained CVE-2026-63219 and CVE-2026-58400 flaws. Ethiack, whose researcher Rafael Castilho reported the issues, said the chain was reachable starting with version 4.0.6 after the formatter endpoint was refactored and the authorization line was dropped, and it fingerprinted 121 internet-exposed GeoNetwork deployments across 39 countries, with 89 percent tied to government-, military-, or national-agency-related environments; no public exploitation in the wild was reported as of disclosure.

    Show sources