Spring Boot is a technology platform tracked across 9 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed January 29, 2026; most recent activity July 22, 2026.
On March 30, 2022, a zero-day remote code execution vulnerability in the Spring Framework, dubbed 'Spring4Shell' and assigned CVE-2022-22965, was disclosed. This vulnerability affects Spring MVC and Spring WebFlux…
On June 8, 2026, Broadcom announced significant investments in security for the Spring and Java ecosystems, which are critical to over half of Fortune 500 companies. This move comes in response to a staggering 1700%…
On April 27, 2026, three critical vulnerabilities were disclosed for the Spring Framework. CVE-2026-40973 allows local attackers to hijack sessions by exploiting predictable temp directory permissions. CVE-2026-40972…
Chainguard has announced the general availability of Chainguard Libraries for Java, which includes CVE remediation for critical and high-severity vulnerabilities in the Spring Boot ecosystem. This initiative addresses…
Two critical vulnerabilities have been identified in Spring Boot's auto-configuration for Elasticsearch and RabbitMQ. CVE-2026-40970 affects Elasticsearch, while CVE-2026-40971 impacts RabbitMQ. Both vulnerabilities…
In a recent cybersecurity incident, attackers exploited an exposed Spring Boot Actuator endpoint to harvest credentials from leaked configuration data. They utilized the OAuth2 Resource Owner Password Credentials (ROPC)…
Security teams are facing significant risks from end-of-life (EOL) open source software due to unpatched vulnerabilities. When vulnerabilities are discovered, maintainers file CVEs with defined affected ranges, but EOL…
On July 21, 2026, Google announced the preview release of CodeMender, a managed AI security agent designed to identify and remediate software vulnerabilities. Integrated into the Gemini Enterprise Agent Platform and AI…
In a study conducted by Irregular in collaboration with Wiz, AI agents successfully solved nine out of ten web security capture-the-flag (CTF) challenges. The challenges were based on real-world vulnerabilities,…