OpenJDK is a technology platform tracked across 17 threat clusters and 28 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity June 17, 2026.
On March 30, 2022, a zero-day remote code execution vulnerability in the Spring Framework, dubbed 'Spring4Shell' and assigned CVE-2022-22965, was disclosed. This vulnerability affects Spring MVC and Spring WebFlux…
On June 8, 2026, Broadcom announced significant investments in security for the Spring and Java ecosystems, which are critical to over half of Fortune 500 companies. This move comes in response to a staggering 1700%…
Dell has released two security updates (DSA-2025-434 and DSA-2025-435) addressing multiple vulnerabilities in PowerFlex Rack and Appliance systems. The updates cover numerous CVEs, including critical vulnerabilities in…
On April 27, 2026, three critical vulnerabilities were disclosed for the Spring Framework. CVE-2026-40973 allows local attackers to hijack sessions by exploiting predictable temp directory permissions. CVE-2026-40972…
Apache OFBiz has critical vulnerabilities that allow attackers to exploit hardcoded keys and bypass authentication. The vulnerabilities, CVE-2026-31986 and CVE-2026-45434, were published on 2026-05-19 and affect all…
Two critical vulnerabilities have been identified in Spring Boot's auto-configuration for Elasticsearch and RabbitMQ. CVE-2026-40970 affects Elasticsearch, while CVE-2026-40971 impacts RabbitMQ. Both vulnerabilities…
Azul has launched a free JVM vulnerability risk assessment to help enterprises identify security gaps in their Java environments. The mean time to exploit (MTTE) for vulnerabilities has drastically decreased from months…
Vulnerabilities have been identified in OpenJDK versions 8, 11, and 21, as well as CRaC JDK 21. The RMI component in these versions allows unauthenticated remote attackers to establish TCP endpoint connections without…
A vulnerability (CVE-2026-22750) was identified in VMware Tanzu Spring Cloud Gateway, where SSL configurations using the property spring.ssl.bundle were ignored, leading to the use of default SSL settings. This issue…
Neo4j has introduced support for post-quantum hybrid key exchange to protect against potential future quantum computer attacks. This technology addresses the Harvest Now, Decrypt Later (HNDL) threat model, where…