A newly disclosed zero-day vulnerability in GeoServer allows for SQL injection and potential remote code execution (RCE). Discovered by researcher q1uf3ng, the flaw has yet to receive a CVE identifier and is already being actively exploited, with hundreds of probing attempts reported by watchTowr shortly after public disclosure on August 12, 2026. The vulnerability resides in the `jsonArrayContains` function, making GeoServer instances susceptible, particularly those with privileged database access.
Security experts advise organizations running GeoServer to urgently assess their exposure, limit access, and monitor for unusual behavior, emphasizing that attackers can leverage such vulnerabilities quickly once they are publicly known. The absence of a patch requires immediate actions to reduce exposure instead of the usual update schedules. GeoServer has a history of being targeted, with past vulnerabilities regularly exploited at scale.