THREAT actors are exploiting an unpatched zero-day vulnerability in GeoServer, identified as an SQL injection issue that may allow remote code execution. Disclosed by researcher q1uf3ng, the vulnerability affects the jsonArrayContains function, which improperly sanitizes inputs. WatchTowr reports that exploitation attempts began within hours of the disclosure, with hundreds recorded from a small number of IP addresses.
Although currently unpatched, organizations using GeoServer are advised to limit public access and monitor for updates, given GeoServer's history of being targeted.