VulnSea

vmware has 64 CVEs on record between 2018 and 2026. Disclosures have slowed: 19 in the last 90 days after 35 in the 90 before. The busiest recent month was June 2026 with 35. The median CVSS is 7.3 (high), with 6 rated critical. 11% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 207 days (6 cases). The dominant weakness classes are CWE-22 (6) and CWE-770 (6). Most affected products: spring_framework (22), cloud_foundation (5), spring_ai (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
11% vs 1% corpus
Median CVSS
7.3
Publish → KEV
207 d median(6)
Last 90 days
19 prev 35

Products

  • spring_framework 22
  • cloud_foundation 5
  • spring_ai 5
  • spring_data_rest 5
  • spring_security 5
  • spring_integration 4
64
Total CVEs
6
Critical
6
CISA KEV
7
Exploited

vmware vulnerabilities

CVEs affecting vmware, newest first. Open any entry for full detail, references, and exploit status.

64 CVEsRSS

CVE-2026-47880Medium· 5.4
3w ago

A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integrat…

A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integrat…

Sunlitvmware · spring_integrationEPSS 0.19%via NVD
CVE-2026-47885High· 7.5
3w ago

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

Twilightvmware · spring_frameworkEPSS 0.26%via NVD
CVE-2026-47889High· 7.5
3w ago

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Twilightvmware · spring_frameworkEPSS 0.25%via NVD
CVE-2026-47883Medium· 6.1PoC
3w ago

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6…

Twilightvmware · spring_frameworkEPSS 0.19%via NVD
CVE-2026-47884Critical· 9.8PoC
3w ago

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

Abyssalvmware · spring_frameworkEPSS 0.42%via NVD
CVE-2026-47886High· 7.5
3w ago

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent…

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent…

Twilightvmware · spring_frameworkEPSS 0.32%via NVD
CVE-2026-47879High· 7.7
3w ago

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Sp…

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Sp…

Twilightvmware · spring_cloud_gatewayEPSS 0.25%via NVD
CVE-2026-47888High· 7.5
3w ago

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 -…

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 -…

Twilightvmware · spring_frameworkEPSS 0.32%via NVD
CVE-2026-47887Medium· 6.1
3w ago

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spri…

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spri…

Sunlitvmware · spring_frameworkEPSS 0.17%via NVD
CVE-2026-47859Medium· 5.4
3w ago

RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size w…

RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size w…

Sunlitvmware · spring_integrationEPSS 0.23%via NVD
CVE-2026-47856Medium· 6.3
3w ago

Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration…

Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration…

Sunlitvmware · spring_integrationEPSS 0.24%via NVD
CVE-2026-47852High· 7.5
3w ago

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

Twilightvmware · spring_aiEPSS 0.20%via NVD
CVE-2026-47851High· 7.5
3w ago

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

Twilightvmware · spring_aiEPSS 0.26%via NVD
CVE-2026-47850Medium· 4.3
3w ago

Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - …

Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - …

Sunlitvmware · spring_data_restEPSS 0.18%via NVD
CVE-2026-47836High· 7.2
3w ago

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud …

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud …

Twilightvmware · spring_cloud_configEPSS 0.14%via NVD
CVE-2026-59318Medium· 6.5
1mo ago

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current…

Sunlitvmware · spring_aiEPSS 0.19%via NVD
CVE-2026-59308Medium· 4.2
1mo ago

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

Sunlitvmware · spring_aiEPSS 0.16%via NVD
CVE-2026-59279High· 7.5
1mo ago

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause t…

Twilightvmware · spring_aiEPSS 0.39%via NVD
CVE-2026-59310Critical· 9.8CISA KEVPoC
1mo ago

vCenter directory-traversal vulnerability

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

HadalVMware · Cloud FoundationEPSS 50%via CVEORG
CVE-2026-41001Medium· 5.3
3mo ago

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable d…

Sunlitvmware · spring_bootEPSS 0.09%via NVD
CVE-2026-40992Medium· 5.0
3mo ago

Spring Boot's Mail auto-configuration does not enable hostname verification

Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected version…

Sunlitvmware · spring_bootEPSS 0.12%via NVD
CVE-2026-40987High· 7.1PoC
3mo ago

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.…

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.…

Midnightvmware · spring_integrationEPSS 0.22%via NVD
CVE-2026-41856High· 7.5
3mo ago

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When…

Twilightvmware · spring_for_graphqlEPSS 0.35%via NVD
CVE-2026-41700High· 8.1
3mo ago

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbi…

Twilightvmware · spring_for_graphqlEPSS 0.19%via NVD
CVE-2026-41699High· 8.1
3mo ago

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a p…

Twilightvmware · spring_for_graphqlEPSS 0.43%via NVD
CVE-2026-41837Medium· 5.3
3mo ago

Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0…

Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0…

Sunlitvmware · spring_data_restEPSS 0.19%via NVD
CVE-2026-41732High· 8.1
3mo ago

JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages

JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to tr…

Twilightvmware · spring_for_apache_pulsarEPSS 0.35%via NVD
CVE-2026-41730Medium· 5.3
3mo ago

Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16…

Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16…

Sunlitvmware · spring_data_restEPSS 0.20%via NVD
CVE-2026-41729High· 8.1PoC
3mo ago

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segm…

Midnightvmware · spring_data_restEPSS 0.39%via NVD
CVE-2026-41728High· 7.5
3mo ago

Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 throu…

Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 throu…

Twilightvmware · spring_data_restEPSS 0.31%via NVD
vmware vulnerabilities (CVEs) · VulnSea