{"id":"CVE-2026-40987","title":"A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.\n\nAffected versions:\nSpring Integration 7.0.0 through 7.…","summary":"A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.\n\nAffected versions:\nSpring Integration 7.0.0 through 7.…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L","cwe":["CWE-22"],"vendor":"vmware","product":"spring_integration","affected":["spring_integration < 5.5.21","spring_integration >= 6.3.0, < 6.3.15","spring_integration >= 6.4.0, < 6.4.12","spring_integration >= 6.5.0, < 6.5.8.1","spring_integration >= 7.0.0, < 7.0.4.1"],"patched":["spring_integration 7.0.4.1"],"published":"2026-06-11","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-40987","references":[{"url":"https://spring.io/security/cve-2026-40987","label":"security@vmware.com"}],"tags":["nvd","exploit-available"],"epss":0.00218,"epssPercentile":0.1247,"ingestedAt":"2026-09-05T13:39:55.139Z","exploits":{"github":1,"githubRepos":["https://github.com/daehyuh/CVE-2026-40987"],"checkedAt":"2026-09-23T07:14:03.844Z"},"exploitAvailable":true,"slug":"CVE-2026-40987","body":"## Overview\n\nA malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.\n\nAffected versions:\nSpring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.\n\n## Affected\n\n- `spring_integration < 5.5.21`\n- `spring_integration >= 6.3.0, < 6.3.15`\n- `spring_integration >= 6.4.0, < 6.4.12`\n- `spring_integration >= 6.5.0, < 6.5.8.1`\n- `spring_integration >= 7.0.0, < 7.0.4.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_integration 7.0.4.1`","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":5179,"id":"CVE-2026-40987","ts":1788887251716,"field":"exploit_available","old":"false","new":"true"},{"seq":4062,"id":"CVE-2026-40987","ts":1788886367677,"field":"exploit_available","old":"true","new":"false"},{"seq":2853,"id":"CVE-2026-40987","ts":1788883034263,"field":"exploit_available","old":"false","new":"true"},{"seq":1882,"id":"CVE-2026-40987","ts":1788882437178,"field":"exploit_available","old":"true","new":"false"},{"seq":979,"id":"CVE-2026-40987","ts":1788881871467,"field":"exploit_available","old":"false","new":"true"}]}