2026-08-15HIGHexploitedGeoServer zero-day exploited within hours of disclosure; fixed in 3.0.1, 2.28.5 and 2.27.6, and now tracked as CVE-2026-76904
GeoServer / GeoTools jsonArrayContains unauthenticated SQL injection, exploited; fixed 2026-08-14 in GeoServer 3.0.1 / 2.28.5 / 2.27.6 (GeoTools 35.1 / 34.5 / 33.6); identifier assigned 2026-08-21
cve · CVE-2026-76904
Coverage
1
first 2026-08-15 → last 2026-09-29
Latest activity
2026-09-29
GeoServer zero-day exploited within hours of disclosure; fixed in 3.0.1, 2.28.5 and 2.27.6, and now tracked…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, transport, energy · regions: europe, switzerland
Sources cited
7
7 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-76904, newest first. Check the date before acting on an older one.
- Upgrade every GeoServer instance backed by a PostGIS data store to 3.0.1, 2.28.5 or 2.27.6 (GeoTools 35.1 / 34.5 / 33.6, CVE-2026-76904), and keep any instance that cannot be upgraded this week off the public internet or behind authenticated access, do not substitute a configuration change, because preferQueryMode=extended is not a mitigation and the vendor advisory offers none. Include Oracle JDBC and H2-backed deployments in the inventory, which NCSC-CH and Field Effect name alongside PostGIS.2026-08-15CVE-2026-76904
- For any instance that was internet-reachable and unpatched between 12 and 14 August, review the PostgreSQL role GeoServer connects as: if it held superuser or pg_execute_server_program, treat the database host as in scope for a compromise assessment rather than only upgrading.2026-08-15CVE-2026-76904
Defender insights
What each entry about CVE-2026-76904 tells a defender to do, newest first.
Latest update · triage
Story timeline
Hunting pivots
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: Unix Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-15/geoserver-jsonarraycontains-unauth-sqli-zeroday-exploited · ATT&CK page ↗
Execution TA0002
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-08-15/geoserver-jsonarraycontains-unauth-sqli-zeroday-exploited · ATT&CK page ↗
Entries about GeoServer / GeoTools jsonArrayContains unauthenticated SQL injection, exploited; fixed 2026-08-14 in GeoServer 3.0.1 / 2.28.5 / 2.27.6 (GeoTools 35.1 / 34.5 / 33.6); identifier assigned 2026-08-21 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- fieldeffect.com1 (14%)
- geoserver.org1 (14%)
- github.com1 (14%)
- hadrian.io1 (14%)
- security-hub.ncsc.admin.ch1 (14%)
- securityweek.com1 (14%)
- thehackernews.com1 (14%)
External references
All cited sources (7)
- geoserver.orgprimaryGeoServer projecthttps://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html
- fieldeffect.comField Effecthttps://fieldeffect.com/blog/early-exploitation-attempts-observed-geoserver-zero-day
- github.comGeoTools (GitHub Security Advisory)https://github.com/geotools/geotools/security/advisories/GHSA-mqjf-5f49-2fjh
- hadrian.ioHadrianhttps://hadrian.io/blog/here-be-dragons-geoserver-pre-auth-sql-injection-to-rce
- security-hub.ncsc.admin.chNCSC Switzerland, Cyber Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12844
- securityweek.comSecurityWeekhttps://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html