<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends]]></title><description><![CDATA[<p dir="auto">Two unpatched flaws in <strong>GeoNetwork</strong>, the open-source geospatial metadata catalog, can be linked into an unauthenticated remote code execution (RCE) chain. The software commonly underpins government and agency geoportals, making the risk particularly acute for public-sector infrastructure.</p>
<p dir="auto">The maintainers addressed both issues in releases <strong>4.4.12</strong> and <strong>4.2.17</strong>, shipped on <strong>July 8, 2026</strong>. Full technical disclosure followed on <strong>August 31</strong>.</p>
<p dir="auto">The vulnerability chain allows an attacker with no prior access to execute arbitrary commands on the underlying server. Given GeoNetwork’s typical deployment at the backend of official mapping and environmental data portals, the exposure could escalate into full server compromise if left unpatched.</p>
<p dir="auto">If you operate an affected instance, consider the following steps:</p>
<ul>
<li>Upgrade to <strong>GeoNetwork 4.4.12</strong> or <strong>4.2.17</strong> immediately.</li>
<li>Audit server logs for suspicious requests targeting catalog or metadata endpoints.</li>
<li>Restrict network access to GeoNetwork administration interfaces until patching is complete.</li>
<li>Review your deployment for any indicators of post-exploitation activity if the service has been publicly exposed.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your team already patched your GeoNetwork backend, or are you still assessing exposure to this chain?</p>
]]></description><link>https://xploitlk.com/topic/237/geonetwork-fixes-unauthenticated-rce-chain-affecting-government-geoportal-backends</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:27:29 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/237.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 06 Sep 2026 12:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>