CVE-2024-36401
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: geoServer is an open source server that allows users to share and edit geospatial data. EPSS 100% (100th percentile).
CISA federal remediation date Aug 5 · date passed
Vulnerabilities · 54 days ago
GeoServer is being used as an execution foothold, not just a vulnerable web app. The exploit turns a map query into an OS command, so a public GeoServer can be made to fetch and run malware straight away instead of just crashing or leaking data.
SANS ISC saw active exploitation in logs tied to CVE-2024-36401. The payload used an `exec()` XPath expression and fetched a Rondo botnet script with `wget`, `busybox wget`, or `curl`, which means exposed GeoServer instances can be pulled into follow-on malware activity as soon as they are hit.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: geoServer is an open source server that allows users to share and edit geospatial data. EPSS 100% (100th percentile).
CISA federal remediation date Aug 5 · date passed
1 source covering this story
Rondo Meets Geoserver - SANS Internet Storm Center
Rondo Meets Geoserver, Author: Johannes Ullrich
Part of the PlainSec briefing for 2026-07-23