CRITICAL
9.8 CVE-2026-78286 Published 27 Aug 2026
GeoServer PHP Object Injection Bug
Worried this affects one of your servers?
GeoServer, a popular open-source geospatial server, is affected by an unauthenticated PHP Object Injection vulnerability in its Geo Controller.
Versions up to and including 8.9.8 are vulnerable.
An attacker can exploit this issue to inject malicious PHP objects, potentially leading to remote code execution.
Reference: CVE-2026-78286 on NVD
← Back to Security News