DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE-2024-36401 is actively exploited via XPath injection in GeoServer’s OGC filter, delivering a multi‑stage shell script through a botnet; patching to the latest GeoServer release mitigates the risk.
Renars Kadzulis@RenarsKadzulisGeneral
The post notes two GeoServer CVEs (RCE and XXE) but offers neither proof of exploitation, patches, nor code, merely referencing the vulnerabilities.
Edgars Jēkabsons 🇪🇺 💙💛@edgarsjDisclosure
A link to a Geoserver vulnerability page for CVE-2024-36401 was shared, but the content does not provide detailed technical information, PoC, exploit code, or patch details.
r0otk3r@r0otk3rDisclosure
The tweet announces CVE-2024-36401, highlighting its critical nature and unauthorized RCE impact on GeoServer, hints at a PoC, and urges patching, but provides no direct exploitation code.
Loginsoft Threat Intel@Loginsoft_IntelActive Exploitation
Cytellite reports that Storm Industries LLC has recently detected activity exploiting CVE-2024-36401.
Loginsoft Threat Intel@Loginsoft_IntelGeneral
The tweet references a detection event for CVE-2024-36401 and provides a link, but lacks any technical details, exploit code, or patch information.
Loginsoft Threat Intel@Loginsoft_IntelGeneral
Cytellite reports a recent detection of activity targeting CVE‑2024‑36401, but provides no technical or exploit details, patches, or evidence of in‑the‑wild exploitation.
ismael Liasini@last_snap999Active Exploitation
CISA reports real‑world exploitation of CVE‑2024‑36401 in GeoServer and urges rapid patching of KEV vulnerabilities.