๐จ ACTIVE EXPLOITATION
- Attackers Probe Unpatched GeoServer SQL Injection Zero-Day
Attackers are actively probing an unpatched GeoServer zero-day.
- GeoServer deployments support government, defense, science, education, engineering and technology organizations.
- The unpatched zero-day affects the jsonArrayContains function and has no CVE identifier.
- Unauthenticated users can inject SQL commands into the database.
- Microsoft SQL Server instances running with administrator permissions could enable remote code execution.
- watchTowr observed hundreds of probing attempts from a small pool of IP addresses, without malicious payloads seen so far. ๐ Source: x.com ยท ๐ Coverage: csoonline.com ยท ๐ via SecurityWeek
๐ CVEs & KEV
- CVE-2026-12949 โ CVSS 9.8 โ Wishlist Member X through 3.34.1 - Unauthenticated Account Takeover via 'mergewith...
- CVE-2026-19792 โ CVSS 7.4 โ Tenda G0 httpd web management interface module setPortMapping buffer overflow...
- CVE-2026-19791 โ CVSS 7.4 โ Tenda G0 httpd web management interface module addStaticRoute stack-based ove...