Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
2026-07-27T01:23:40Z•bbf69d6235d8d2d6f2efe454d2fc0100926652899aa3ca5fcc9a10149a86436c
CVE-2026-63030CDG 3ESAFENET CDGGeoServerSQL injectionWordPressactive exploitationcross-site scriptingdefault passwordsscanningunauthenticated remote code executionweak credentialsweb application security
What happened
SANS Internet Storm Center reporting highlights active scanning for weak logins and known vulnerabilities in ESAFENET CDG 3 document management systems, including SQL injection, cross-site scripting, and default-password issues. The feed also reports active exploitation of WordPress core SQL injection vulnerability CVE-2026-63030, which can enable unauthenticated remote code execution. Additional entries discuss GeoServer-related activity and autonomous attacker operations, but provide insufficient detail for specific vulnerability attribution.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- bbf69d6235d8d2d6f2efe454d2fc0100926652899aa3ca5fcc9a10149a86436c
- Enrichment time
- 2026-07-27T01:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.