🔴 CVE-2025-58360

GeoServer has an unauthenticated XML External Entity (XXE) vulnerability in the WMS GetMap feature that can be exploited directly over the network. CISA has confirmed active exploitation in the wild.

← Back to Overview
HIGH_RISK
Risk Level
8.2
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-11-25

Added to CISA KEV: 2025-12-11 16 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2025-12-11)

Here's what is known about the CVE-2025-58360 vulnerability exploitation, based on the provided search results:

  • CISA KEV Status: CISA has added CVE-2025-58360 to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation in the wild [1][2]. CISA maintains the KEV catalog as an authoritative source of vulnerabilities that have been exploited [3].
  • Active Exploitation: The addition to the KEV catalog is based on evidence of active exploitation [1][2].
  • Targeted Attacks: While the search results confirm active exploitation, they do not explicitly state whether CVE-2025-58360 has been used in targeted attacks.
  • Internet-facing applications: While the search results confirm active exploitation, they do not explicitly state whether CVE-2025-58360 affects internet-facing applications.
  • Attack Vectors and Exploitation Methods: The search results do not provide specific details on the attack vectors or exploitation methods used for this vulnerability.
  • Technical Details: The search results lack specific technical details regarding the exploitability of this vulnerability.

Sources

  1. CISA Adds Five Known Exploited Vulnerabilities to Catalog

    CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2016 ...See more…

  2. CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.See more…

  3. Known Exploited Vulnerabilities Catalog - CISA

    CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their ...See more…