← Back

Wire · technology

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Published

2 September 2026

Topic

technology

Sectors

Government & Space

Geography

Europe

Source

Read at thehackernews.com

Verified

Fusion42 · 2 September 2026 · Fusion42 review

GeoNetwork patched two chained vulnerabilities that allow unauthenticated remote code execution on government geoportal backends, affecting Spatial Data Infrastructure in Europe and beyond. The flaws involve missing authorization on file uploads and unsafe XSLT processor configuration.

This Wire brief sits within Fusion42's coverage of Government & Space.

◆ The Wire takeaway

Government and agency geoportal backends have a critical exploit vector now closed. You need to check your Spatial Data Infrastructure stack this week and patch GeoNetwork without delay.

Coverage

1 source · 2 Sep 2026

Related on Wire

Topics

Government & Spacegeonetworkrceunauthenticatedgovtechsecurity-patch