GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
- Posted on September 2, 2026
- By The Hacker News
- 1 Views
- 1 min read
GeoNetwork has released critical security patches addressing two formatter vulnerabilities that could be exploited together to achieve unauthenticated remote code execution on government geospatial infrastructure. The vulnerability chain poses significant risks to public sector geoportals worldwide. Security researchers have documented the flaw, though active exploitation attempts remain unreported. Organizations operating GeoNetwork instances are urged to apply patches immediately to protect sensitive geospatial data and prevent unauthorized system access.
Summary auto-generated by AI from the original publisher's content. Editorial standards.