isc.sans.edu 7/22/2026, 7:40:21 PM · external

Rondo botnet revives Geoserver flaw, exploiting CVE-2024-36401

Rondo botnet revives Geoserver flaw, exploiting CVE-2024-36401
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
Rondo botnet

THE article, authored by Johannes Ullrich, discusses a recent resurgence of a known attack associated with the Rondo botnet targeting Geoserver. The attack exploits a vulnerability (CVE-2024-36401) related to X-Path expression evaluation in Geoserver, which is a tool for geographic information systems. The specifics of the attack involve a crafted request that executes commands via a shell, potentially downloading malicious files.

The author reflects on the tactics of the Rondo botnet and its historical context in cybersecurity, noting that remnants of the attack may still be present.

View full article

Article by CyberSIXT