Critical GeoServer Vulnerability CVE-2025-58360 Added to CISA’s Known Exploited Vulnerabilities Catalog

Listen to this Post

Featured Image
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability in GeoServer, tracked as CVE-2025-58360, to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion highlights the severity of the flaw and its potential impact on both federal and private sector networks. GeoServer, an open-source server widely used for sharing and editing geospatial data, is now under scrutiny due to an XML External Entity (XXE) vulnerability that could allow attackers to access internal files or trigger server-side requests. With a CVSS score of 8.2, this flaw represents a high-risk security threat.

Overview of the Vulnerability

GeoServer versions 2.26.0 through 2.26.1 and versions 2.25.x prior to 2.25.6 were found to contain an XXE flaw in the /geoserver/wms GetMap endpoint. The vulnerability arises because XML input provided to this endpoint was not properly sanitized, enabling attackers to embed external entities within XML requests. These malicious requests could potentially expose sensitive internal files or even initiate server-side requests, posing significant operational risks. The flaw has been patched in versions 2.25.6, 2.26.3, and 2.27.0, and administrators are urged to update immediately.

Canada’s Cyber Centre confirmed on November 28, 2025, that exploits targeting this vulnerability are already active in the wild, underlining the urgent need for organizations to take preventative measures. While no detailed technical reports of ongoing attacks are publicly available, open-source intelligence confirms active exploitation attempts.

Historical Context and Previous Exploitation

This is not the first instance of GeoServer vulnerabilities being exploited. In September 2025, CISA revealed that threat actors had leveraged an unpatched GeoServer flaw, CVE-2024-36401, to breach a U.S. federal civilian agency. This critical remote code execution (RCE) vulnerability, with a CVSS score of 9.8, enabled attackers to move laterally across the network, compromising additional servers, including web and SQL servers. Attackers deployed web shells like China Chopper and scripts for persistence, remote access, and privilege escalation, while using living-off-the-land techniques to avoid detection.

Following Binding Operational Directive (BOD) 22-01, federal agencies are required to remediate vulnerabilities listed in the KEV catalog by their specified due dates, with CISA mandating that the CVE-2025-58360 flaw be addressed by January 1st, 2026. Private organizations are also strongly advised to review their systems and apply necessary updates.

What Undercode Say:

The inclusion of CVE-2025-58360 in CISA’s KEV catalog reflects a broader trend in cybersecurity: the increasing targeting of open-source infrastructure. GeoServer’s popularity in handling geospatial data makes it an attractive target for threat actors seeking lateral movement opportunities and sensitive data access. XXE vulnerabilities, while often overlooked, can be highly destructive, enabling attackers to bypass traditional firewalls and gain insights into internal network structures.

Federal agencies’ slow patch cycles exacerbate these risks. Historical incidents show that attackers are quick to exploit known vulnerabilities once they are publicly disclosed. The prior exploitation of CVE-2024-36401 demonstrates the ease with which threat actors can move laterally once initial access is achieved, often leaving minimal traces thanks to living-off-the-land techniques.

From a strategic perspective, the criticality of CVE-2025-58360 lies not only in its immediate impact but also in its potential for long-term operational disruption. Geospatial servers are integral to numerous public services, from emergency response mapping to infrastructure planning. A successful attack could compromise essential services and create cascading operational risks.

Organizations should adopt a multi-layered approach: immediate patching, network segmentation, continuous monitoring for abnormal XML requests, and incident response readiness. Furthermore, federal and private organizations must prioritize open-source security audits, as vulnerabilities in widely deployed software often carry systemic implications.

The rapid confirmation of active exploits by Canada’s Cyber Centre indicates that threat actors are continuously monitoring open-source vulnerability disclosures. This real-time threat environment necessitates proactive measures rather than reactive responses. Patch management should no longer be a quarterly task but an ongoing process with automated vulnerability scanning and immediate remediation for critical flaws.

CISA’s KEV catalog serves as both a warning and a regulatory tool. Its directives underline the need for compliance not just in federal systems but also across the private sector. Organizations relying on GeoServer should view this alert as a call to action: the risk is immediate, and the opportunity for mitigation is narrow.

Fact Checker Results:

✅ CVE-2025-58360 is confirmed in the CISA Known Exploited Vulnerabilities catalog.
✅ Exploits targeting this GeoServer vulnerability are already active in the wild.
❌ There are no public technical details on the methods used for active exploitation yet.

Prediction:

📊 The urgency around GeoServer vulnerabilities will likely increase, with more threat actors attempting automated exploitation of XXE flaws. Federal agencies and private organizations that delay patching could face lateral attacks affecting critical infrastructure.
📊 We may see additional vulnerabilities in open-source geospatial software targeted in 2026 as attackers recognize the high operational impact and relatively slow patching cycles.
📊 Organizations prioritizing proactive monitoring, network segmentation, and immediate patching will mitigate risk, while those ignoring these alerts could experience significant breaches.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon