Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Government and military agencies using GeoNetwork
Incident: Unauthenticated RCE vulnerability chain involving CVE-2026-63219 and CVE-2026-58400.
Impact: Complete server compromise and unauthorized operating system command execution.
Attacker: Unidentified threat actors
Analysis: The vulnerability chains a missing authorization check on a formatter upload endpoint with an unsafe XSLT processor. By uploading a malicious stylesheet and triggering it via a GET request, attackers can achieve full remote code execution. The risk is amplified by the software’s widespread use in government and military spatial data infrastructures.
Recommendations: Update GeoNetwork to version 4.4.12 or 4.2.17 immediately; Audit all internet-facing geospatial services for vulnerable versions; Implement strict network segmentation for metadata catalog backends
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source