TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

GeoServer Targeting on the Rise

2026-02-11 · Read original ↗

ATT&CK techniques detected

8 predictions
T1190Exploit Public-Facing Application
85%
"- 9082, a thinkphp php injection rce, remains a significant concern. this vulnerability enables attackers to inject malicious php code into thinkphp applications. organizations using thinkphp should update to the latest version and implement input validation to prevent exploitati…"
T1190Exploit Public-Facing Application
66%
"geoserver targeting on the rise introduction the f5 labs sensor intel series provides an in - depth analysis of the most significant vulnerabilities and their exploitation trends. this article highlights the top 10 cves, their activity levels, and their potential impact on organi…"
T1595.002Vulnerability Scanning
63%
"##ver - related requests, the most common user agents presented as mainstream browsers, often using generic or incomplete chrome and webkit strings. older browser versions were common, and there was also a smaller set of requests using headless tooling indicators. a meaningful nu…"
T1587.004Exploits
46%
"##2 and cve - 2024 - 4577 have both climbed in rankings, showing increased activity levels. cve - 2022 - 24847 rounds out the top five, although its activity has slightly decreased compared to the previous month. these trends highlight the persistent exploitation of certain vulne…"
T1190Exploit Public-Facing Application
45%
"##points. those metadata fields are frequently enough to distinguish “ is wms alive ” probes from “ is wms parsing attacker - controlled xml ” attempts, even if you do not capture request bodies. cve - 2024 - 36401 : unauthenticated rce through ogc request parameters cve - 2024 -…"
T1588.006Vulnerabilities
37%
"##2 and cve - 2024 - 4577 have both climbed in rankings, showing increased activity levels. cve - 2022 - 24847 rounds out the top five, although its activity has slightly decreased compared to the previous month. these trends highlight the persistent exploitation of certain vulne…"
T1587.004Exploits
34%
"in table 1 ). cve - 2025 - 55182 follows with nearly 20, 000 instances, reflecting its critical severity and high exploitation potential. cve - 2019 - 9082, cve - 2024 - 4577, and cve - 2022 - 24847 also show significant activity, with thousands of exploitation attempts each. not…"
T1588.006Vulnerabilities
31%
"##ver - related requests, the most common user agents presented as mainstream browsers, often using generic or incomplete chrome and webkit strings. older browser versions were common, and there was also a smaller set of requests using headless tooling indicators. a meaningful nu…"

Summary

Sensor Intel Series: January 2026 CVE Trends