CVE-2025-58360General(geoserver / geoserver)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for geoserver geoserver systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0.

5.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-01-01. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-611

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • geoserver

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • 15 mentions across 13 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 12 signals
  • General: 7 classified signals
  • Peaked 12d ago at 2 mentions (2026-01-27); latest day: 1
  • 15 total mentions across 13 days

Affected systems

Vendors
Products
geoserver

Deep dive

Activity timeline15 mentions / 13d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-29: 1Mentions · 2026-01-31: 1Mentions · 2026-02-01: 2Mentions · 2026-03-03: 1Mentions · 2026-03-22: 1Mentions · 2026-03-23: 1Mentions · 2026-04-04: 1Mentions · 2026-04-08: 1Mentions · 2026-04-11: 1Mentions · 2026-04-15: 1Mentions · 2026-05-25: 1Mentions · 2026-06-25: 1PoC Mentioned / Linked · 2026-02-01: 1PoC Mentioned / Linked · 2026-03-03: 1Active Exploitation · 2026-01-27: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-11: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-01: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-15: 1Technical Details · 2026-05-25: 1Technical Details · 2026-06-25: 101-2701-2901-3102-0103-0303-2203-2304-0404-0804-1104-1505-2506-25
Signal classification5 categories
General
746.7%
Active Exploitation
320.0%
PoC
213.3%
Disclosure
213.3%
Exploit
16.7%
Referenced assets12 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-272
Active Exploitation1General1
2026-01-291
General1
2026-01-311
General1
2026-02-012
General1PoC1
2026-03-031
PoC1
2026-03-221
General1
2026-03-231
Disclosure1
2026-04-041
Exploit1
2026-04-081
Active Exploitation1
2026-04-111
Active Exploitation1
2026-04-151
General1
2026-05-251
General1
2026-06-251
Disclosure1
Full discourse15 posts
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet presents a list of the top 25 CVEs that are currently being exploited in the wild, highlighting ongoing attacks without providing further technical or mitigation details.

    070921.2K
    5.5K followersView on X
  • Renars Kadzulis@RenarsKadzulis
    Disclosure

    @tikums Ja banka vienā naktī pazaudē visu naudu, kuru tai uzticēts sargāt, vai tiešām vainīgs MI, kas, iespējams, palīdzējis zagļiem? Nopietni? Tas nekas, ka par GeoServer kritiskām ievainojamībām zināms kopš 2024.g. (CVE-2024-36401: RCE), kopš 2025.g. (CVE-2025-58360: XXE).

    Post summary

    The post references two GeoServer CVEs (RCE and XXE) but provides no evidence of exploitation, PoC, or patch availability, serving mainly as a disclosure notice.

    120113346
    607 followersView on X
  • reverseame@reverseame
    Disclosure

    GeoServer WMS GetMap XML External Entity Injection Vulnerability (CVE-2025-58360) #GeoServer #WMS #XEE #Injection #Vulnerability https://helixguard.ai/blog/CVE-2025-58360/

    Post summary

    The tweet announces the discovery of an XML External Entity injection flaw in GeoServer WMS GetMap (CVE-2025-58360), highlighting its nature but offering no PoC, exploit code, or patch guidance.

    01012584
    21.8K followersView on X
  • Divert@Divert_Security
    Active Exploitation

    GeoServer XXE CVE-2025-58360: Publicly disclosed 11/25/25, first probes observed/blocked for our customers on 12/3/25, added by #CISA to #KEV on 12/11/25. This example was sourced from #Proton66. https://t.co/zJGlDz2d2K

    Post summary

    CVE‑2025‑58360 is a GeoServer XXE vulnerability that was publicly disclosed in November and has seen active probing and blocking in early December, now listed on CISA’s KEV.

    0001168
    10 followersView on X
  • Himadri Singh@LittleSun4lower
    General

    I just completed GeoServer: CVE-2025-58360 room on TryHackMe! Explore the GeoServer XXE vulnerability CVE-2025-58360 from exploit to defense. https://tryhackme.com/room/geoservercve202558360?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #learning #consistency

    Post summary

    The tweet promotes a TryHackMe room that covers the GeoServer XXE vulnerability (CVE-2025-58360) but provides no direct proof of concept, exploit code, or remediation details.

    00010210
    14 followersView on X
  • TheGentlemanHacker@mld_77
    General

    I just completed GeoServer: CVE-2025-58360 room on TryHackMe! Explore the GeoServer XXE vulnerability CVE-2025-58360 from exploit to defense. https://tryhackme.com/room/geoservercve202558360?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=5f9b52519f63ac139bb7e225 #tryhackme via @tryhackme

    Post summary

    The tweet announces completion of a TryHackMe training room focused on the GeoServer XXE vulnerability CVE-2025-58360, providing only high‑level details without discussing PoC, exploitation, or patch status.

    00001269
    1.7K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2025-58360 Exploit in the wild confirmed for CVE-2025-58360 (CVSS 9.8). OSGeo GeoServer contains an improper restriction of XML external entity reference vulnera... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post reports that CVE‑2025‑58360 is actively being exploited in the wild, giving its CVSS score and vulnerability nature, yet provides no PoC, exploit code, or patch information.

    00010349
    5.6K followersView on X
  • JOJIN@jojin_1709
    PoC

    I just completed GeoServer: CVE-2025-58360 room on TryHackMe! Explore the GeoServer XXE vulnerability CVE-2025-58360 from exploit to defense. https://tryhackme.com/room/geoservercve202558360?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=6778f917b00cfed91bc168fd #tryhackme via @tryhackme

    Post summary

    The tweet announces completion of a TryHackMe room that offers a proof‑of‑concept for GeoServer’s XXE vulnerability CVE‑2025‑58360, including an exploit tutorial and defensive measures.

    0001092
    3 followersView on X
  • LaMonte Ward@wardlamonte5
    General

    I just completed GeoServer: CVE-2025-58360 room on TryHackMe! Explore the GeoServer XXE vulnerability CVE-2025-58360 from exploit to defense. https://tryhackme.com/room/geoservercve202558360?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=68e66aca35889828805e08a4 #tryhackme via @tryhackme

    Post summary

    The author finished a TryHackMe room that teaches exploitation and defense of GeoServer’s XXE vulnerability CVE-2025-58360, but the statement provides no exploit details, patches, or evidence of active attacks.

    00010109
    2 followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    General

    "GeoServer: CVE-2025–58360 | Tryhackme" by Aaron #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@AT24/geoserver-cve-2025-58360-tryhackme-f760e934282f

    Post summary

    The text merely references a Medium article about CVE‑2025‑58360 without providing concrete details, PoC, or exploitation information.

    00001114
    481 followersView on X
  • Roman@mrBr4un
    Exploit

    I just completed GeoServer: CVE-2025-58360 room on TryHackMe! Explore the GeoServer XXE vulnerability CVE-2025-58360 from exploit to defense. https://tryhackme.com/room/geoservercve202558360?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=68639866ce8287add0b55c97 #tryhackme через @tryhackme

    Post summary

    The post highlights a TryHackMe room focused on attacking and defending a GeoServer XXE vulnerability (CVE‑2025‑58360), but does not provide a PoC, exploit code, or evidence of active exploitation.

    00000310
    55 followersView on X
  • 刘灏 LiuHao@GuanShanZhe
    General

    I just completed GeoServer: CVE-2025-58360 room on TryHackMe! Explore the GeoServer XXE vulnerability CVE-2025-58360 from exploit to defense. https://tryhackme.com/room/geoservercve202558360?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=67c32163fcb8c49ab2766b1c #tryhackme 来自 @tryhackme

    Post summary

    The message highlights a TryHackMe training room focused on the GeoServer CVE‑2025‑58360 XXE vulnerability but offers no PoC, exploit code, or patch details.

    00000135
    145 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    PoC

    I just completed GeoServer: CVE-2025-58360 room on TryHackMe! Explore the GeoServer XXE vulnerability CVE-2025-58360 from exploit to defense. https://tryhackme.com/room/geoservercve202558360?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The post advertises a TryHackMe room that demonstrates the GeoServer XXE vulnerability CVE-2025-58360, providing a PoC and guidance from exploitation to defense, with no mention of active exploitation or patching.

    0000084
  • Xaliqverdi Ragimli@XaliqRagimli27
    General

    I just completed GeoServer: CVE-2025-58360 room on TryHackMe! Explore the GeoServer XXE vulnerability CVE-2025-58360 from exploit to defense. https://tryhackme.com/room/geoservercve202558360?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=67dc4b1b476ea9a83c6e91e6 #tryhackme via @tryhackme

    Post summary

    The message announces a TryHackMe learning room focused on the GeoServer XXE vulnerability (CVE‑2025‑58360), covering exploitation and defense techniques, but provides no specific PoC code, patch information, or evidence of active exploitation.

    0000060
    1 followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    General

    "TryHackMe | GeoServer: CVE-2025-58360 | WriteUp" by Axoloth #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/h7w/tryhackme-geoserver-cve-2025-58360-writeup-2d364d1dbe04

    Post summary

    The tweet shares a link to a Medium writeup about GeoServer CVE‑2025‑58360 but provides no technical details, PoC, exploit code, or mention of active exploitation or patch information.

    0000074
    479 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgeoservergeoserver---

Explore more