CVE-2026-40972 is a vulnerability tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed April 27, 2026; most recent activity April 28, 2026.
On April 27, 2026, three critical vulnerabilities were disclosed for the Spring Framework. CVE-2026-40973 allows local attackers to hijack sessions by exploiting predictable temp directory permissions. CVE-2026-40972…