• News/
  • https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-geoserver-flaw/

CISA orders feds to patch actively exploited Geoserver flaw

BleepingComputer
·
Sergiu Gatlan
·
Published Dec 12, 2025
·
Updated

CISA has ordered U.S. federal agencies to patch a critical GeoServer vulnerability now actively exploited in XML External Entity (XXE) injection attacks. In such attacks, an XML input containing a reference to an external entity is processed by a weakly configured XML parser, allowing threat actors to launch denial-of-service attacks, access confidential data, or perform Server-Side Request Forgery (SSRF) to interact with internal systems. The security flaw (tracked as CVE-2025-58360) flagged by CISA on Thursday is an unauthenticated XML External Entity (XXE) vulnerability in GeoServer 2.26.1 and prior versions (an open-source server for sharing geospatial data over the Internet) that can be exploited to retrieve arbitrary files from vulnerable servers. "An XML External Entity (XXE) vulnerability was identified affecting GeoServer 2.26.1 and prior versions. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap," a GeoServer advisory explains. "However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request." The Shadowserver Internet watchdog group now tracks 2,451 IP addresses with GeoServer fingerprints, while Shodan reports over 14,000 instances exposed online. ​CISA has now added CVE-2025-58360 to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks and ordering Federal Civilian Executive Branch (FCEB)...

Read full article

Affected Software

2 affected components
GeoServer geoserver=2.26.1
GeoServer geoserver
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The main topic of this article is the CISA's order for federal agencies to patch a critical vulnerability in GeoServer that is being actively exploited.

2

What security implications are discussed in the article?

The article discusses the risks associated with the XML External Entity (XXE) injection attacks on the GeoServer vulnerability.

3

What software is affected by the vulnerability mentioned?

The software affected by the vulnerability is GeoServer.

4

Who is required to take action according to the CISA order?

U.S. federal agencies are required to take action and patch the vulnerability.

5

What type of attack is being exploited targeting GeoServer?

The attacks targeting GeoServer involve XML External Entity (XXE) injection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203