Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks

CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks

Posted on December 12, 2025December 12, 2025 By CWS

An pressing warning a few important safety flaw in OSGeo GeoServer, a extensively used open-source geographic data-sharing server.

CISA has added the vulnerability to its Recognized Exploited Vulnerabilities (KEV) catalog, indicating that risk actors are actively leveraging this zero-day flaw in assaults focusing on each private and non-private sectors.

The newly disclosed vulnerability, tracked as CVE-2025-58360, is assessed as an Improper Restriction of XML Exterior Entity (XXE) Reference.

This safety hole exists throughout the software’s dealing with of XML enter. Particularly involving the /geoserver/wms endpoint throughout GetMap operations.

FieldDetailsCVE IDCVE-2025-58360NameOSGeo GeoServer XXE VulnerabilityDescriptionXML enter in /geoserver/wms GetMap is just not correctly restricted, permitting exterior XML entities.Associated CWECWE-611ActionApply vendor fixes, observe BOD 22-01 for cloud companies, or cease utilizing the product.

Safety researchers have decided that the software program fails to limit exterior entities in XML requests correctly.

By exploiting this weak spot, distant attackers can outline malicious exterior entities of their requests. Profitable exploitation might enable unauthorized actors to view recordsdata on the server.

Work together with backend or exterior programs (Server-Aspect Request Forgery), or trigger denial-of-service situations.

The affirmation of energetic exploitation prompted CISA to intervene, requiring federal civilian govt department (FCEB) businesses to instantly safe their programs.

In accordance with Binding Operational Directive (BOD) 22-01, CISA has mandated that each one FCEB businesses should determine and mitigate this vulnerability by January 1, 2026.

Whereas the mandate applies solely to federal businesses, CISA strongly urges all organizations that use OSGeo GeoServer to prioritize this replace.

The brief remediation window displays the severity of the risk and the energetic nature of present campaigns. Directors are suggested to use the related vendor mitigations instantly.

If patches are usually not but out there for particular configurations, organizations ought to observe CISA’s steering for cloud companies. Take into account quickly discontinuing the usage of the affected product till it may be secured.

Comply with us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:0Day, Attacks, CISA, Exploited, GeoServer, OSGeo, Vulnerability, Warns

Post navigation

Previous Post: CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
Next Post: $320,000 Paid Out at Zeroday.Cloud for Open Source Software Exploits

Related Posts

Cloud Atlas Hacker Group Exploiting Office Vulnerabilities to Execute Malicious Code Cloud Atlas Hacker Group Exploiting Office Vulnerabilities to Execute Malicious Code Cyber Security News
Microsoft Details Mitigations Against React2Shell RCE Vulnerability in React Server Components Microsoft Details Mitigations Against React2Shell RCE Vulnerability in React Server Components Cyber Security News
2,000+ Devices Hacked Using Weaponized Social Security Statement Themes 2,000+ Devices Hacked Using Weaponized Social Security Statement Themes Cyber Security News
Everest Hacking Group Allegedly Claims Breach of Nissan Motors Everest Hacking Group Allegedly Claims Breach of Nissan Motors Cyber Security News
Windows SMB Client Vulnerability Enables Attacker to Own Active Directory Windows SMB Client Vulnerability Enables Attacker to Own Active Directory Cyber Security News
New Linux Vulnerability ‘DirtyClone’ Grants Root Access New Linux Vulnerability ‘DirtyClone’ Grants Root Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark