Vulnerabilities & Exploits · Web App Attack

GeoServer Becomes a Botnet Launch Point

GeoServer is being used as an execution foothold, not just a vulnerable web app. The exploit turns a map query into an OS command, so a public GeoServer can be made to fetch and run malware straight away instead of just crashing or leaking data.

SANS ISC saw active exploitation in logs tied to CVE-2024-36401. The payload used an `exec()` XPath expression and fetched a Rondo botnet script with `wget`, `busybox wget`, or `curl`, which means exposed GeoServer instances can be pulled into follow-on malware activity as soon as they are hit.

1 source · Jul 22

CVE-2024-36401

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: geoServer is an open source server that allows users to share and edit geospatial data. EPSS 100% (100th percentile).

CISA federal remediation date Aug 5 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-07-22

Every edition of this story: GeoServer Becomes a Botnet Launch Point

More from today