CISA has ordered U.S. federal agencies to patch a critical GeoServer vulnerability now actively exploited in XXE injection attacks.