CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog

Based on evidence of active exploitation in the field, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity security vulnerability affecting OSGeo GeoServer to its Known Exploited Vulnerabilities (KEV) list on Thursday.

The vulnerability in question is CVE-2025-58360 (CVSS score: 8.2), an unauthenticated XML External Entity (XXE) problem that affects versions 2.26.0 through 2.26.1 and all versions before and including 2.25.5. Versions 2.25.6, 2.26.2, 2.27.0, 2.28.0, and 2.28.1 have patches for it. The issue was reported by XBOW, a vulnerability finding platform driven by artificial intelligence (AI).

According to CISA, OSGeo GeoServer has an incorrect restriction of XML external entity reference vulnerability that arises when the program accepts XML input via a certain endpoint /geoserver/wms operation GetMap and may enable an attacker to declare external entities within the XML request read more about CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *