Two vulnerabilities in GeoNetwork, the open-source geospatial metadata catalog, can be chained to achieve unauthenticated remote code execution (RCE). The flaws affect many government and agency geoportal backends that rely on GeoNetwork. Fixes were shipped in versions 4.4.12 and 4.2.17 on July 8, 2026, with full vulnerability details published on August 31, 2026. GeoNetwork originated at the United Nations Food and Agriculture Organization and is widely used in public sector infrastructure. The chained attack requires no authentication, making it particularly dangerous for exposed government systems. Organizations running GeoNetwork are urged to upgrade immediately to the patched versions.