# Spring Framework patches four RCE vulnerabilities

Published: 2026-06-16 · Severity: high
Canonical: https://vorant.io/reports/cb0ed889-d87b-5c79-8818-924e1b5dd511/spring-framework-patches-four-rce-vulnerabilities

> Spring released patches for four vulnerabilities in Spring Boot and Spring for GraphQL enabling remote code execution.

The French CERT (CERT-FR) has published an advisory covering four security vulnerabilities affecting multiple versions of Spring Boot and Spring for GraphQL. The flaws enable remote code execution, though vendor-specific details remain unspecified. The affected products span numerous version branches of Spring Boot Enterprise, Spring Boot OSS, standard Spring Boot, and Spring for GraphQL.

Affected versions include Spring Boot 2.7.x prior to 2.7.34, 3.3.x prior to 3.3.20, 3.4.x prior to 3.4.17, Spring Boot Enterprise 3.5.x prior to 3.5.15, 4.0.x prior to 4.0.6.1, and corresponding OSS releases. Spring for GraphQL versions 1.0.x through 2.0.x are also impacted across multiple branches. Organizations running these versions should prioritize patching to the fixed releases.

The vendor published security bulletins on June 10, 2026 for CVE-2026-41001, CVE-2026-41699, CVE-2026-41700, and CVE-2026-41856. Given Spring's widespread deployment in enterprise Java applications, organizations should review their Spring dependencies and apply the available patches.

## Mentioned in this report

- Vulnerabilities: CVE-2026-41001, CVE-2026-41699, CVE-2026-41700, CVE-2026-41856

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0759

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/cb0ed889-d87b-5c79-8818-924e1b5dd511/spring-framework-patches-four-rce-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
