VulnSea

VMware has 66 CVEs on record between 2018 and 2026. Disclosures have slowed: 21 in the last 90 days after 35 in the 90 before. The busiest recent month was June 2026 with 35. The median CVSS is 7.3 (high), with 6 rated critical. 11% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 207 days (6 cases). The dominant weakness classes are CWE-22 (6) and CWE-770 (6). Most affected products: spring_framework (22), spring_security (6), cloud_foundation (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
11% vs 1% corpus
Median CVSS
7.3
Publish → KEV
207 d median(6)
Last 90 days
21 prev 35

Products

  • spring_framework 22
  • spring_security 6
  • cloud_foundation 5
  • spring_ai 5
  • spring_data_rest 5
  • spring_integration 4
66
Total CVEs
6
Critical
6
CISA KEV
7
Exploited

VMware vulnerabilities

CVEs affecting VMware, newest first. Open any entry for full detail, references, and exploit status.

66 CVEsRSS

CVE-2026-41729High· 8.1PoC
3mo ago

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segm…

▾ Midnightvmware · spring_data_restEPSS 0.39%via NVD
CVE-2026-41728High· 7.5
3mo ago

Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 throu…

Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 throu…

▾ Twilightvmware · spring_data_restEPSS 0.31%via NVD
CVE-2026-41727Medium· 6.5
3mo ago

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt coun…

▾ Sunlitvmware · spring_for_apache_kafkaEPSS 0.24%via NVD
CVE-2026-41717High· 8.1
3mo ago

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-al…

▾ Twilightvmware · spring_data_mongodbEPSS 0.33%via NVD
CVE-2026-41714Medium· 4.0
3mo ago

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected vers…

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected vers…

▾ Sunlitvmware · spring_advanced_message_queuing_protocolEPSS 0.13%via NVD
CVE-2026-41706Medium· 6.1
3mo ago

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versi…

▾ Sunlitvmware · spring_securityEPSS 0.21%via NVD
CVE-2026-41696Medium· 5.9
3mo ago

Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter

Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expr…

▾ Sunlitvmware · spring_data_mongodbEPSS 0.26%via NVD
CVE-2026-41694Low· 3.7
3mo ago

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a d…

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a d…

▾ Sunlitvmware · spring_securityEPSS 0.15%via NVD
CVE-2026-41003High· 7.6
3mo ago

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 …

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 …

▾ Twilightvmware · spring_securityEPSS 0.20%via NVD
CVE-2026-40993High· 7.3
3mo ago

An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of veri…

An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of veri…

▾ Twilightvmware · spring_securityEPSS 0.20%via NVD
CVE-2026-40988High· 7.5
3mo ago

An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memor…

An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memor…

▾ Twilightvmware · spring_securityEPSS 0.33%via NVD
CVE-2026-41854Medium· 4.2
3mo ago

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0…

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0…

▾ Sunlitvmware · spring_frameworkEPSS 0.12%via NVD
CVE-2026-41853Medium· 5.3
3mo ago

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

▾ Sunlitvmware · spring_frameworkEPSS 0.19%via NVD
CVE-2026-41852Low· 3.7
3mo ago

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic.…

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic.…

▾ Sunlitvmware · spring_frameworkEPSS 0.18%via NVD
CVE-2026-41851Medium· 5.3
3mo ago

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Sprin…

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Sprin…

▾ Sunlitvmware · spring_frameworkEPSS 0.36%via NVD
CVE-2026-41850High· 7.5
3mo ago

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS)

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource cons…

▾ Twilightvmware · spring_frameworkEPSS 0.36%via NVD
CVE-2026-41848Low· 3.7
3mo ago

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(St…

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(St…

▾ Sunlitvmware · spring_frameworkEPSS 0.32%via NVD
CVE-2026-41846Medium· 5.9
3mo ago

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulne…

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulne…

▾ Sunlitvmware · spring_frameworkEPSS 0.15%via NVD
CVE-2026-41845High· 7.1
3mo ago

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.…

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.…

▾ Twilightvmware · spring_frameworkEPSS 0.16%via NVD
CVE-2026-41844Medium· 4.2
3mo ago

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect…

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect…

▾ Sunlitvmware · spring_frameworkEPSS 0.14%via NVD
CVE-2026-41843Medium· 5.9
3mo ago

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

▾ Sunlitvmware · spring_frameworkEPSS 0.37%via NVD
CVE-2026-41842High· 7.5
3mo ago

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.…

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.…

▾ Twilightvmware · spring_frameworkEPSS 0.40%via NVD
CVE-2026-41841Medium· 5.9
3mo ago

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3…

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3…

▾ Sunlitvmware · spring_frameworkEPSS 0.34%via NVD
CVE-2026-41838Medium· 4.8
3mo ago

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.…

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.…

▾ Sunlitvmware · spring_frameworkEPSS 0.17%via NVD
CVE-2026-41007High· 7.5
3mo ago

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2;…

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2;…

▾ Twilightvmware · spring_hateoasEPSS 0.30%via NVD
CVE-2026-41006High· 7.5
3mo ago

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations…

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations…

▾ Twilightvmware · spring_hateoasEPSS 0.28%via NVD
CVE-2026-22739High· 8.6PoC
6mo ago

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

▾ Midnightvmware · spring_cloud_configEPSS 1.2%via NVD
CVE-2025-22225High· 8.2CISA KEV0day
1y ago

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

▾ Abyssalvmware · cloud_foundationEPSS 1.00%via NVD
CVE-2021-21985Critical· 9.8CISA KEVPoC
5y ago

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to por…

▾ Hadalvmware · vcenter_serverEPSS 100%via NVD
CVE-2021-21983Medium· 6.5PoC
5y ago

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locati…

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locati…

▾ Twilightvmware · cloud_foundationEPSS 69%via NVD
VMware vulnerabilities (CVEs) — page 2 · VulnSea