Hackers Exploiting Unpatched GeoServer Zero-Day
2026-08-14T07:23:58Z•7ed1b8bf58f152bd68dfb4b972e7b096e1a945a5f15c1179487b8b313979fcdf
CVE-2026-59310CVE-2026-71362Adobe CommerceFortinetGeoServerSQL injectionVMware vCenterWindowsactive exploitationauthentication bypassbrowser session hijackingcredential theftdirectory traversalinfostealermacOS malwareprivilege escalationremote code executionvulnerability disclosurezero-day
What happened
SecurityWeek RSS feed covering active exploitation and disclosure of critical vulnerabilities, including a GeoServer SQL injection zero-day enabling remote code execution, an actively targeted Adobe Commerce flaw (CVE-2026-71362), a critical VMware vCenter directory traversal vulnerability (CVE-2026-59310) enabling arbitrary code execution, Fortinet authentication flaws, and a Windows zero-day exploit granting SYSTEM privileges. The feed also reports macOS infostealer activity and broader cybersecurity business and policy developments.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 7ed1b8bf58f152bd68dfb4b972e7b096e1a945a5f15c1179487b8b313979fcdf
- Enrichment time
- 2026-08-14T07:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.