ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Malware Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

GeoServer RCE: Critical Flaw CVE-2024-36401 Under Active Attack

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. GeoServer RCE: Critical Flaw CVE-2024-36401 U...
  • All articles
  • Categories
  • Tags
  • Statuses

GeoServer RCE: Critical Flaw CVE-2024-36401 Under Active Attack

Critical GeoServer Vulnerability Under Active ExploitationOrganisations across Spain and the EU that rely on GeoServer to publish geospatial data are...

Critical GeoServer Vulnerability Under Active Exploitation

Organisations across Spain and the EU that rely on GeoServer to publish geospatial data are facing a critical security challenge. A severe flaw, tracked as CVE-2024-36401, is now being actively exploited in the wild, allowing attackers to achieve remote code execution (RCE) without any authentication. This means that if your GeoServer instance is exposed to the internet, it could be compromised with minimal effort.

Digital fortress with cracked gate and shield padlock symbolizing server protection

The vulnerability originates in how GeoServer and its underlying GeoTools library handle certain property names. In default configurations, specific parameters can be evaluated as XPath expressions, enabling malicious strings to trigger RCE through a component called commons-jxpath. In practice, an attacker can send specially crafted requests to vulnerable endpoints, executing arbitrary commands on your server.

Attack Surface and Real-World Impact

The attack surface is not limited to a single service. Multiple OGC endpoints are affected, including:

  • WFS requests such as GetFeature and GetPropertyValue
  • WMS operations like GetMap, GetFeatureInfo, and GetLegendGraphic
  • WPS Execute requests

If your server exposes these endpoints and is reachable from the internet, the risk is immediate. Documented incidents show a clear pattern: initial access via CVE-2024-36401, internal network reconnaissance, lateral movement, and persistence through web shells. Tools like China Chopper have been observed, which allow attackers to maintain control even after reboots or superficial cleanups.

This is not a theoretical threat. Confirmed intrusions have already occurred, including breaches in US federal agencies, highlighting the severity and real-world impact. For Spanish and EU organisations, especially those in the public sector or hosting geospatial services, this vulnerability demands urgent attention.

Immediate Remediation Steps

The first priority is to update GeoServer to a patched version. The following releases include fixes:

  • 2.22.6
  • 2.23.6
  • 2.24.4
  • 2.25.2

If you cannot patch immediately, consider the temporary mitigation of removing the gt-complex x.y.jar file from your deployment. However, be aware that this may break functionality or even prevent startup in some environments. Always test this in a staging environment first and plan for a quick rollback if needed.

Beyond patching, reducing exposure is critical. Implement network-level controls such as IP allowlisting, mandatory VPN access, or place a reverse proxy with authentication and filtering rules in front of GeoServer. These measures significantly lower the likelihood of exploitation while you complete the update.

Post-Exploitation Detection and Response

If your server has been exposed to the internet without patches, treat it as potentially compromised. Conduct a thorough investigation for indicators of compromise, including:

  • Web shells or suspicious files
  • Unexpected processes or services
  • Unusual outbound connections

Rotate all credentials associated with the system and review logs from GeoServer and your web front-end for anomalous WFS, WMS, or WPS requests, especially those containing unusual filters or parameters.

Having a tested incident response plan and continuous monitoring is essential. The faster you detect a breach, the less damage an attacker can do. For organisations without dedicated security teams, partnering with a managed security service provider can help ensure 24/7 vigilance.

Proactive Server Protection with Abuse Shield

While patching is the first line of defence, proactive protection is vital to prevent future attacks. ALMC.es offers Abuse Shield, a comprehensive solution that centralises server security. It automatically blocks malicious IPs, manages fail2ban across multiple machines, and maintains a shared reputation feed across all your servers. This means if one server detects a threat, all others are immediately protected.

Abuse Shield is designed for system administrators, hosting companies, and SMEs with their own servers. It simplifies security management, reduces response times, and strengthens your overall cybersecurity posture. By integrating Abuse Shield, you can focus on your core business while we handle the constant monitoring and blocking of malicious actors.

Don't wait for the next critical vulnerability to hit your infrastructure. Take proactive steps today to secure your servers and protect your data.

Related

  • Citrix NetScaler RCE: CISA Orders Urgent Patching
  • Citrix NetScaler CVE-2026-8452: Act Now to Shield Your Edge
  • Citrix NetScaler RCE: CISA Orders Urgent Patching
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Security Audits and Pentesting
Cloud Migration (AWS, Azure, Google Cloud)
API Integrations & Microservices
Cloud Security (AWS, Azure, Google Cloud)
Server Management & Monitoring
Relacionados
  • GeoServer CVE-2024-36401: Act Fast to Shield Your Servers
    Cybersecurity · 13 minutes ago
  • SharePoint Server Critical Flaw: Immediate Steps to Secure Your Farm
    Cybersecurity · 13 minutes ago
  • VMware vCenter CVE-2026-59310: Urgent Patch Guide for EU Admins
    Cybersecurity · 13 minutes ago
  • Guard Your Code: The GhostSplice MCP Attack and How to Stay Safe
    Cybersecurity · 13 minutes ago
  • CISA KEV Update: Six Actively Exploited Flaws Including NetScaler, Linux, SQL Server
    Cybersecurity · 1 hour ago
  • SLEEPWALKER Backdoor: A Stealthy Threat for Windows Servers
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • Folderr MCP Server
    Productivity
  • Instagram DMs
    Communication
  • WireMCP
    Development
  • Nimiq MCP Server
    Database
  • GitHub Projects V2
    Version Control
  • gNMIBuddy
    Development
  • k8s Pilot
    Cloud Service
  • HeyBeauty
    Development
  • APISIX-MCP
    Cloud Service
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar