Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2355 articles · 122490 vulns · 35/41 feeds (7d)
← Back to list
—
CVE-2026-22740EXPLOITED
vmware · spring framework

Multiple Vulnerabilities in Spring Framework

Description

Multiple security vulnerabilities have been identified in the Spring Framework as detailed in the Spring security bulletins dated April 17, 2026. These include CVE-2026-22740, CVE-2026-22741, and CVE-2026-22745. Specific technical details and affected versions are documented in the official Spring security bulletins.

Affected Products

VendorProductVersions
vmwarespring framework5.3.0 to 5.3.47, 6.1.0 to 6.1.26, 6.2.0 to 6.2.17, 7.0.0 to 7.0.6

Related News (2 articles)

Tier B
CCCS Canada2d ago
Spring security advisory (AV26-373)
→ No new info (linked only)
Tier B
CERT-FR4d ago
Multiples vulnérabilités dans Spring Framework (20 avril 2026)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedApr 20, 2026
Last enriched2d agov2
Tags
multiple vulnerabilitiesspring frameworksecurity bulletin
Trending Score31
Source articles2
Independent2
Info Completeness7/14
Missing: cvss, epss, cwe, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALPRE-CVE
Critical Vulnerabilities in Spring Boot
Trending: 29
CRITICALCVE-2026-22738
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. 
Trending: 2
HIGHCVE-2026-22719EXPKEV
VMware Aria Operations command injection vulnerability
HIGHCVE-2026-22720
VMware Aria Operations stored cross-site scripting vulnerability
CRITICALCVE-2026-22732
Under Some Conditions Spring Security HTTP Headers Are not Written

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 20, 2026
Actively Exploited
Apr 20, 2026
Exploit Available
Apr 20, 2026
Discovered by ZDM
Apr 20, 2026
Updated: affectedVersions, severity, exploitAvailable, activelyExploited
Apr 21, 2026

Version History

v2
Last enriched 2d ago
v2Tier B2d ago

Added affected versions for Spring Framework and updated severity to HIGH, indicating that the vulnerabilities are actively exploited.

affectedVersionsseverityexploitAvailableactivelyExploited
via CCCS Canada
v13d ago

Initial creation