The U.S. Cybersecurity and Infrastructure Security Agency
(CISA) on Thursday added a high-severity security flaw impacting
OSGeo GeoServer to its Known Exploited Vulnerabilities (KEV)
catalog, based on evidence of active exploitation in the wild. The
vulnerability in question is CVE-2025-58360 (CVSS score: 8.2), an
unauthenticated XML External Entity (XXE) flaw that affects all
versions prior to
Read more https://thehackernews.com/2025/12/cisa-flags-actively-exploited-geoserver.html

