An unpatched GeoServer SQL injection is already being probed hours after disclosure
Disclosed on August 12, 2026, an unauthenticated SQL injection in GeoServer’s jsonArrayContains function can lead to remote code execution, and no patch is available yet. Attackers are already probing exposed instances: isolate yours before the fix lands.