GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public Vulnerability Report GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public Do Son August 18, 2026 0 TL;DR A GeoServer unauthenticated SQL injection flaw is under active attack. It lives in the jsonArrayContains filter... Read More Read more about GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public