VORANT. Threat Intelligence Sign in Get the full feed

Spring Framework patches 15 CVEs across multiple modules

high vulnerability

VMware Spring released fixes for 15 vulnerabilities affecting AMQP, Data Commons, Data REST, Security, and other modules, enabling code execution, DoS, and security-policy bypass.

On June 9, 2026, VMware Spring released coordinated security advisories addressing 15 CVEs across multiple Spring Framework modules. The affected components include Spring AMQP (versions 2.4.x through 4.0.x), Spring Data Commons, Spring Data KeyValue, Spring Data MongoDB, Spring Data Relational, Spring Data REST, and Spring Security (versions 1.5.x through 7.0.x). The vulnerabilities enable attackers to execute arbitrary code, bypass security policies, and trigger denial-of-service conditions.

The French national CERT (CERT-FR) issued advisory CERTFR-2026-AVI-0719 recommending immediate patching. Affected organizations should upgrade to the specified fixed versions for each module: AMQP 2.4.18/3.1.16/3.2.11/4.0.4, Data modules 2.7.20/3.3.17/3.4.15/3.5.12/4.0.6 (with variant versions for MongoDB and REST), and Security 1.5.8/5.7.24/5.8.26/6.3.17/6.4.17/6.5.11/7.0.6.

Given the widespread deployment of Spring Framework in enterprise Java applications and the severity of the flaws (arbitrary code execution), organizations running Spring-based applications should treat this as a high-priority patching cycle. The simultaneous disclosure of 15 CVEs suggests a comprehensive security audit uncovered systemic issues across the Spring ecosystem.

Mentioned in this report

Vulnerabilities CVE-2026-40988CVE-2026-40993CVE-2026-41003CVE-2026-41008CVE-2026-41694CVE-2026-41695CVE-2026-41696CVE-2026-41697CVE-2026-41701CVE-2026-41711CVE-2026-41716CVE-2026-41717CVE-2026-41719CVE-2026-41721CVE-2026-41729

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0719

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free