Wire · technology
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 2 September 2026 · Fusion42 review
GeoNetwork patched two chained vulnerabilities that allow unauthenticated remote code execution on government geoportal backends, affecting Spatial Data Infrastructure in Europe and beyond. The flaws involve missing authorization on file uploads and unsafe XSLT processor configuration.
This Wire brief sits within Fusion42's coverage of Government & Space.
◆ ◆ The Wire takeaway
Government and agency geoportal backends have a critical exploit vector now closed. You need to check your Spatial Data Infrastructure stack this week and patch GeoNetwork without delay.
◆ Coverage
1 source · 2 Sep 2026
◆ Related on Wire
◆ Topics