CVE-2023-25158Active Exploitation(geotools / geotools)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch geotools geotools systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filter expression language parsing, encoding and execution against a range of datastore. SQL Injection Vulnerabilities have been found when executing OGC Filters with JDBCDataStore implementations. Users are advised to upgrade to either version 27.4 or to 28.2 to resolve this issue. Users unable to upgrade may disable `encode functions` for PostGIS DataStores or enable `prepared statements` for JDBCDataStores as a partial mitigation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • geotools

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked 1d ago at 2 mentions (2026-08-15); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
geotools

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-15: 2Mentions · 2026-08-21: 1Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-08-21: 1Patch / Workaround · 2026-08-15: 2Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-15: 2Technical Details · 2026-08-21: 108-1508-21
Signal classification2 categories
Active Exploitation
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-152
Active Exploitation1Patch1
2026-08-211
Active Exploitation1
Full discourse3 posts
  • The Hacker News@TheHackersNews
    Patch

    ⚡ UPDATE: GeoServer has patched the actively targeted SQL injection flaw. The issue affects PostGIS-backed deployments and is a regression of CVE-2023-25158. Update now: https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html https://t.co/q1UD8Htz7T

    Post summary

    GeoServer has released a patch for an actively targeted SQL injection vulnerability in PostGIS‑backed deployments, referencing CVE‑2023‑25158. No PoC or exploit details are provided in the update.

    4160761547.2K
    2.4M followersView on X
  • AlexAImaginator@TraffAlex
    Active Exploitation

    🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — August 15, 2026 1️⃣ MACOS SCREEN SHARING FLAW EXPLOITED FOR MONERO MINING Attackers are actively exploiting CVE-2026-65400, a vulnerability in Apple's macOS Screen Sharing feature, to install Monero cryptocurrency miners on compromised systems. The flaw affects Macs with port 5900 exposed to the internet, allowing unauthenticated remote access. Apple has already released emergency updates to patch the vulnerability, but security researchers warn that many internet-facing machines may remain unpatched and at risk. System administrators should immediately verify their macOS installations are up to date and ensure VNC ports are not unnecessarily exposed. 🔹 @TheHackersNews 2️⃣ SABLE SQUIRREL SPENDS $7 MILLION ON EXPIRED DOMAINS FOR CYBERCRIME A sophisticated cybercrime group known as Sable Squirrel has been identified spending nearly $7 million acquiring expired domains to build a massive infrastructure for malicious operations. The group now controls over 10,000 domains that facilitate illegal streaming services, online gambling platforms, and malware command-and-control communications. At least 31,000 distinct malware samples have been observed communicating with these domain networks, making it one of the largest domain-based cybercrime infrastructures documented to date. 🔹 @TheHackersNews 3️⃣ SAP COMMERCE CLOUD CRITICAL FLAW SEEKING ACTIVE EXPLOITATION CVE-2026-58231, a CVSS 10.0 critical vulnerability in SAP Commerce Cloud, is already under active exploitation attempts just three days after the patch was released. The flaw allows unauthenticated attackers to execute arbitrary code remotely on affected systems. Security researchers emphasize that this is a race against time — organizations running SAP Commerce Cloud must apply the vendor patch immediately, as the exploit code is circulating in threat actor communities and being actively leveraged in targeted campaigns. 🔹 @TheHackersNews 4️⃣ GEOSERVER PATCHES ACTIVELY TARGETED SQL INJECTION REGRESSION GeoServer has released a patch for an actively exploited SQL injection vulnerability affecting PostGIS-backed deployments. The flaw is a regression of CVE-2023-25158, meaning organizations that previously fixed the original issue may have been re-exposed by subsequent updates. The vulnerability allows attackers to execute arbitrary SQL commands against the database backend, potentially leading to full data compromise. All GeoServer administrators using PostGIS should update immediately and verify their deployment is no longer vulnerable. 🔹 @TheHackersNews 5️⃣ HACKERS ARRESTED OVER €30 MILLION BANK FRAUD Law enforcement agencies have arrested several individuals responsible for a €30 million bank fraud scheme that exploited a vulnerability in a critical service provider's infrastructure. The attackers leveraged the flaw to intercept and manipulate financial transactions across multiple banking institutions. The arrests highlight the growing importance of securing third-party service providers in the financial supply chain, as a single compromised vendor can cascade into massive losses across their entire customer base. 🔹 @BleepinComputer 6️⃣ SANDWORM DEPLOYS TROJANIZED WIREGUARD AGAINST UKRAINIAN IT WORKERS The Sandworm threat group, linked to Russian military intelligence, has launched a targeted campaign against Ukrainian IT professionals using trojanized WireGuard VPN clients. Operating through its UAC-0145 cluster, the group is conducting fake job interviews to distribute the compromised software. This social engineering approach makes the attack particularly effective, as victims believe they are participating in legitimate recruitment processes. The use of WireGuard — typically a trusted open-source VPN tool — demonstrates adversaries' increasing sophistication in weaponizing legitimate software. 🔹 @Huntio 7️⃣ EVOOO1BOT LINUX BOTNET TURNS ROUTERS INTO TRAFFIC RELAY NODES A new Mirai-based Linux botnet called Evooo1Bot is targeting internet-facing gateways and compromising routers to convert them into SOCKS5 traffic relay nodes. This modular malware allows attackers to route their malicious traffic through compromised infrastructure, making attribution and blocking significantly more difficult. Network operators should ensure their gateway devices are running firmware with the latest security patches and monitor for unusual outbound traffic patterns that may indicate infection. 🔹 @BleepinComputer 💭 The threat landscape this week demonstrates a clear pattern: attackers are weaponizing trust. Whether it's trojanized open-source VPN software, expired domains that look legitimate, or service providers whose customers assume are secure — the common thread is exploiting relationships and tools that organizations rely on without question. Defenders need to shift from trusting by default to verifying continuously. Which of these threats should your organization prioritize patching first? 👇 #Cybersecurity #InfoSec #ZeroDay #DataBreach #ThreatIntelligence #OpenSource #Privacy

    Post summary

    Several high‑severity CVEs are confirmed to be in active exploitation, with vendors releasing patches and advisories; immediate patching is essential.

    01030285
    2.7K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    GeoServer のゼロデイ脆弱性 CVE-N/A の悪用を観測:SQLi による RCE の可能性 https://iototsecnews.jp/2026/08/13/geoserver-zero-day-targeted-in-active-exploitation-attempts-can-lead-to-rce/ 地理空間データを扱うオープンソースソフトウェアの GeoServer において、認証を必要としない SQL インジェクションの欠陥が確認されました。この問題は CVE-2023-25158 の回帰であり、特定のデータベース設定環境において、攻撃者によるリモートコード実行 (RCE) が引き起こされる危険性があります。公開直後からインターネット上での悪用試行が観測されており、被害の防止には迅速な対応が必要です。影響を受ける環境の運用者は、修正された最新バージョンへの速やかなアップデート/外部からの不要なアクセスの制限/ログの継続的な監視が求められます。 #GeoServer #Vulnerability #ZeroDay

    Post summary

    The article reports that GeoServer CVE-2023-25158 is currently being actively exploited via unauthenticated SQL injection leading to potential remote code execution, and it advises immediate patching and hardening measures.

    00000198
    509 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgeotoolsgeotools---

Explore more