SPIN Unprocessed September 2, 2026 ai_technology cybersecurity
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
View original on thehackernews.comOverview
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and
SpinGraph analysis pending — check back after processing.
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
More from The Hacker News
View all →- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
- Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
- 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO