VORANT. Threat Intelligence Sign in Get the full feed

Spring Framework patches four RCE vulnerabilities

high vulnerability

Spring released patches for four vulnerabilities in Spring Boot and Spring for GraphQL enabling remote code execution.

The French CERT (CERT-FR) has published an advisory covering four security vulnerabilities affecting multiple versions of Spring Boot and Spring for GraphQL. The flaws enable remote code execution, though vendor-specific details remain unspecified. The affected products span numerous version branches of Spring Boot Enterprise, Spring Boot OSS, standard Spring Boot, and Spring for GraphQL.

Affected versions include Spring Boot 2.7.x prior to 2.7.34, 3.3.x prior to 3.3.20, 3.4.x prior to 3.4.17, Spring Boot Enterprise 3.5.x prior to 3.5.15, 4.0.x prior to 4.0.6.1, and corresponding OSS releases. Spring for GraphQL versions 1.0.x through 2.0.x are also impacted across multiple branches. Organizations running these versions should prioritize patching to the fixed releases.

The vendor published security bulletins on June 10, 2026 for CVE-2026-41001, CVE-2026-41699, CVE-2026-41700, and CVE-2026-41856. Given Spring's widespread deployment in enterprise Java applications, organizations should review their Spring dependencies and apply the available patches.

Mentioned in this report

Vulnerabilities CVE-2026-41001CVE-2026-41699CVE-2026-41700CVE-2026-41856

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0759

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free