Hackers Exploiting Unpatched GeoServer Zero-Day

2026-08-14T07:23:58Z7ed1b8bf58f152bd68dfb4b972e7b096e1a945a5f15c1179487b8b313979fcdf
CVE-2026-59310CVE-2026-71362Adobe CommerceFortinetGeoServerSQL injectionVMware vCenterWindowsactive exploitationauthentication bypassbrowser session hijackingcredential theftdirectory traversalinfostealermacOS malwareprivilege escalationremote code executionvulnerability disclosurezero-day

What happened

SecurityWeek RSS feed covering active exploitation and disclosure of critical vulnerabilities, including a GeoServer SQL injection zero-day enabling remote code execution, an actively targeted Adobe Commerce flaw (CVE-2026-71362), a critical VMware vCenter directory traversal vulnerability (CVE-2026-59310) enabling arbitrary code execution, Fortinet authentication flaws, and a Windows zero-day exploit granting SYSTEM privileges. The feed also reports macOS infostealer activity and broader cybersecurity business and policy developments.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
7ed1b8bf58f152bd68dfb4b972e7b096e1a945a5f15c1179487b8b313979fcdf
Enrichment time
2026-08-14T07:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers Exploiting Unpatched GeoServer Zero-Day · Baitaphish