# Spring Framework patches 15 CVEs across multiple modules

Published: 2026-06-10 · Severity: high
Canonical: https://vorant.io/reports/35a74438-fef5-4a7f-89ad-cae6bc624ce6/spring-framework-patches-15-cves-across-multiple-modules

> VMware Spring released fixes for 15 vulnerabilities affecting AMQP, Data Commons, Data REST, Security, and other modules, enabling code execution, DoS, and security-policy bypass.

On June 9, 2026, VMware Spring released coordinated security advisories addressing 15 CVEs across multiple Spring Framework modules. The affected components include Spring AMQP (versions 2.4.x through 4.0.x), Spring Data Commons, Spring Data KeyValue, Spring Data MongoDB, Spring Data Relational, Spring Data REST, and Spring Security (versions 1.5.x through 7.0.x). The vulnerabilities enable attackers to execute arbitrary code, bypass security policies, and trigger denial-of-service conditions.

The French national CERT (CERT-FR) issued advisory CERTFR-2026-AVI-0719 recommending immediate patching. Affected organizations should upgrade to the specified fixed versions for each module: AMQP 2.4.18/3.1.16/3.2.11/4.0.4, Data modules 2.7.20/3.3.17/3.4.15/3.5.12/4.0.6 (with variant versions for MongoDB and REST), and Security 1.5.8/5.7.24/5.8.26/6.3.17/6.4.17/6.5.11/7.0.6.

Given the widespread deployment of Spring Framework in enterprise Java applications and the severity of the flaws (arbitrary code execution), organizations running Spring-based applications should treat this as a high-priority patching cycle. The simultaneous disclosure of 15 CVEs suggests a comprehensive security audit uncovered systemic issues across the Spring ecosystem.

## Mentioned in this report

- Vulnerabilities: CVE-2026-40988, CVE-2026-40993, CVE-2026-41003, CVE-2026-41008, CVE-2026-41694, CVE-2026-41695, CVE-2026-41696, CVE-2026-41697, CVE-2026-41701, CVE-2026-41711, CVE-2026-41716, CVE-2026-41717, CVE-2026-41719, CVE-2026-41721, CVE-2026-41729

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0719

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/35a74438-fef5-4a7f-89ad-cae6bc624ce6/spring-framework-patches-15-cves-across-multiple-modules.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
