# GeoNetwork Flaws Expose Government Mapping Portals in 39 Countries to Remote Takeover

*Wednesday, September 2, 2026 at 10:07 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-02T10:07:28.952Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/16604.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Critical vulnerabilities in GeoNetwork software could let attackers seize control of government geoportals without a password, with 121 exposed systems identified across 39 countries and nearly 90% tied to state, military or national agencies.

A security hole in a widely used mapping tool has created a new global headache for governments and public agencies that publish official data online.

Researchers have disclosed that GeoNetwork, an open‑source platform for running digital map portals, contains flaws that allow remote code execution without authentication. In plain terms, that means an attacker who can reach a vulnerable server over the internet may be able to run their own commands on it, without needing a username or password.

Cybersecurity firm Ethiack scanned the internet and found 121 exposed GeoNetwork deployments running affected versions across 39 countries. Around 89% of those were associated with government, military or national‑agency entities, the firm reported, underscoring how concentrated the risk is in public‑sector systems.

The maintainers of GeoNetwork have released fixes in versions 4.4.12 and 4.2.17. Systems running earlier releases are considered vulnerable. Until agencies apply the patches or otherwise protect the servers, the affected geoportals could be used as entry points for further attacks inside official networks.

GeoNetwork is often used to share spatial data such as land records, infrastructure maps and environmental information. While these reports do not list specific countries or datasets, the fact that so many deployments belong to central and defense‑related bodies raises the prospect that sensitive information or connected systems could be exposed if attackers exploit the weaknesses.

The disclosure lands amid a broader pattern of cyber campaigns that blend technical exploits with social engineering. The U.S. Department of Justice recently said 255 fake freelance accounts sent malicious Excel files to around 80,000 users, infecting thousands with TVRAT, a remote‑access tool that gave operators control over victims’ machines. An extradited Russian man now faces federal charges in connection with that operation.

Together, the cases highlight how both obscure infrastructure software and everyday office tools can be turned into attack vectors against governments and large organizations. The key signals to watch now are how quickly public bodies patch vulnerable GeoNetwork instances, whether any intrusions tied to the flaw are confirmed, and if threat‑intelligence firms begin to attribute exploitation to particular state or criminal actors.
