CISA has revealed that attackers breached the network of an unnamed U.S. federal civilian executive branch (FCEB) agency last year after compromising an unpatched GeoServer instance. The security bug (tracked as CVE-2024-36401) is a critical remote code execution (RCE) vulnerability patched on June 18, 2024. CISA added the flaw to its catalog of actively exploited vulnerabilities roughly one month later, after multiple security researchers shared proof-of-concept exploits online [1, 2, 3], demonstrating how to gain code execution on exposed servers. While the cybersecurity agency did not provide any details on how the flaws were being exploited in the wild, threat monitoring service Shadowserver observed CVE-2024-36401 attacks starting on July 9, 2024, while OSINT search engine ZoomEye was tracking over 16,000 GeoServer servers that were exposed online. Two days after the first attacks were detected, threat actors gained access to a U.S. federal agency's GeoServer server and compromised another one roughly two weeks later. In the next stage of the attack, they moved laterally through the agency's network, breaching a web server and an SQL server. "On each server, they uploaded (or attempted to upload) web shells such as China Chopper, along with scripts designed for remote access, persistence, command execution, and privilege escalation," CISA said in a Tuesday advisory. "Once inside the organization's network, the cyber threat actors primarily relied on brute force techniqu...
CISA says hackers breached federal agency using GeoServer exploit
BleepingComputer
·Sergiu Gatlan
·Published Sep 23, 2025
·Updated
Affected Software
1 affected component
GeoServer geoserver