{"total":2,"items":[{"id":519,"title":"CVE-2026-58400: core-geonetwork, actief misbruikt","original_title":"CVE-2026-58400: core-geonetwork, actief misbruikt","source_rating":null,"summary":"GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any sty","ai":false,"actions":[],"url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70645","type":"advisory","language":"en","published_at":"2026-09-02T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["geonetwork"],"cves":[{"id":"CVE-2026-58400","cvss":9.1,"epss":0.01187,"epss_percentile":0.66754,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.1,"epss_max":0.01187,"source_count":1,"ncsc":null,"source":{"slug":"euvd","name":"ENISA EU Vulnerability Database","category":"vulnerability","country":"EU","license":"ENISA, hergebruik met bronvermelding","reuse":"open"},"bundle":null},{"id":520,"title":"CVE-2026-63219: core-geonetwork, actief misbruikt","original_title":"CVE-2026-63219: core-geonetwork, actief misbruikt","source_rating":null,"summary":"GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatte","ai":false,"actions":[],"url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70647","type":"advisory","language":"en","published_at":"2026-09-02T00:00:00+00:00","severity":"hoog","priority":48,"vendors":["geonetwork"],"cves":[{"id":"CVE-2026-63219","cvss":8.6,"epss":0.00466,"epss_percentile":0.37973,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["ENISA EUVD"],"kev_ransomware":false,"cvss_max":8.6,"epss_max":0.00466,"source_count":1,"ncsc":null,"source":{"slug":"euvd","name":"ENISA EU Vulnerability Database","category":"vulnerability","country":"EU","license":"ENISA, hergebruik met bronvermelding","reuse":"open"},"bundle":null}]}