top of page
perceptive_background_267k.jpg

GeoServer RCE Exploited in CoinMiner Campaigns (Campaign)

Published:

24 January 2026 at 00:00:00

Alert date:

12 January 2026 at 13:00:50

Source:

threats.wiz.io

Click to open the original link from this advisory

Threat actors are actively exploiting CVE-2024-36401, a remote code execution vulnerability in GeoServer, to deploy cryptocurrency miners. The vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable GeoServer instances. Multiple threat actors have been systematically scanning for exposed GeoServer installations since the vulnerability's disclosure in 2024. The exploitation involves deploying coinminer malware on compromised systems. This represents an active campaign targeting organizations running vulnerable GeoServer instances for cryptocurrency mining operations.

Technical details

Mitigation steps:

Affected products:

GeoServer

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page