HackMyIP
← Back to News
2026-08-14 SecurityWeek

Hackers Exploit Unpatched GeoServer Zero-Day Within Hours of Disclosure

Zero-DayVulnerabilityThreat Intel

Threat actors began exploiting an unpatched zero-day vulnerability in GeoServer within hours of its public disclosure, according to attack surface management firm WatchTowr. The security defect, an SQL injection flaw in GeoServer's jsonArrayContains function—a filter expression used to query JSON array fields in PostGIS and Oracle JDBC data stores—can be leveraged to achieve remote code execution (RCE). The vulnerability was originally disclosed on Wednesday by security researcher q1uf3ng.

The flaw stems from user-supplied arguments being improperly sanitized before being encoded into database queries, which under certain configurations enables full RCE. WatchTowr's Jake Knott reported that the firm observed hundreds of exploitation attempts originating from a small number of source IPs almost immediately after the disclosure went public. Security teams can use a WHOIS lookup to investigate suspicious source addresses and a port scanner to identify exposed GeoServer instances across their networks.

While attackers have so far only used the exploit to probe vulnerable systems, WatchTowr warns that escalation is likely. GeoServer has a track record of being targeted at scale, with multiple vulnerabilities already listed in CISA's Known Exploited Vulnerabilities catalog. With no patch currently available, organizations running GeoServer should restrict public access, monitor for vendor fixes, and audit their environments for signs of compromise.

GeoServer remains a widely adopted open-source platform for sharing and processing geospatial data across government, agriculture, telecommunications, and transit sectors—making the urgency of mitigation critical for any organization with an exposed instance.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →