Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2355 articles · 122471 vulns · 35/41 feeds (7d)
← Back to list
EST
PRE-CVEPATCHED
vmware · spring boot

Critical Vulnerabilities in Spring Boot

72% confidence

Description

Multiple critical vulnerabilities affecting Spring Boot versions prior to 4.0.6, 3.5.14, 3.4.16, 3.3.19, and 2.7.33. Users are advised to update to the fixed versions to mitigate these vulnerabilities.

Affected Products

VendorProductVersions
vmwarespring boot< 4.0.6, < 3.5.14, < 3.4.16, < 3.3.19, < 2.7.33

Related News (1 articles)

Tier B
CCCS Canada4h ago
Spring security advisory (AV26-386)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.0.6
PublishedApr 23, 2026
Last enriched4h ago
Tags
criticalspringspring bootsecurity advisory
Trending Score30
Source articles1
Independent1
Info Completeness6/14
Missing: cve_id, cvss, epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-22740EXP
Multiple Vulnerabilities in Spring Framework
Trending: 31
CRITICALCVE-2026-22738
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. 
Trending: 2
HIGHCVE-2026-22719EXPKEV
VMware Aria Operations command injection vulnerability
HIGHCVE-2026-22720
VMware Aria Operations stored cross-site scripting vulnerability
CRITICALCVE-2026-22732
Under Some Conditions Spring Security HTTP Headers Are not Written

Pin to Dashboard

Verification

State: reported
Confidence: 72%

Vulnerability Timeline

CVE Published
Apr 23, 2026
Patch Available
Apr 23, 2026
Discovered by ZDM
Apr 23, 2026