View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Attackers Probe Unpatched GeoServer SQL Injection Zero-Day

๐Ÿšจ ACTIVE EXPLOITATION

  • Attackers Probe Unpatched GeoServer SQL Injection Zero-Day Attackers are actively probing an unpatched GeoServer zero-day.
    • GeoServer deployments support government, defense, science, education, engineering and technology organizations.
    • The unpatched zero-day affects the jsonArrayContains function and has no CVE identifier.
    • Unauthenticated users can inject SQL commands into the database.
    • Microsoft SQL Server instances running with administrator permissions could enable remote code execution.
    • watchTowr observed hundreds of probing attempts from a small pool of IP addresses, without malicious payloads seen so far. ๐Ÿ“„ Source: x.com ยท ๐Ÿ“Ž Coverage: csoonline.com ยท ๐Ÿ‘ via SecurityWeek

๐Ÿ”“ CVEs & KEV

  • CVE-2026-12949 โ€” CVSS 9.8 โ€” Wishlist Member X through 3.34.1 - Unauthenticated Account Takeover via 'mergewith...
  • CVE-2026-19792 โ€” CVSS 7.4 โ€” Tenda G0 httpd web management interface module setPortMapping buffer overflow...
  • CVE-2026-19791 โ€” CVSS 7.4 โ€” Tenda G0 httpd web management interface module addStaticRoute stack-based ove...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check