Spring4Shell is a high-severity remote code execution vulnerability in the Spring Framework (notably CVE-2022-22965) that can allow unauthenticated attackers to execute arbitrary Java code on vulnerable servers when Spring MVC applications are misconfigured (e.g., running on Tomcat/Jetty).
Spring4Shell is a vulnerability tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed December 3, 2025; most recent activity July 24, 2026.
Spring4Shell is a high-severity remote code execution vulnerability in the Spring Framework (notably CVE-2022-22965) that can allow unauthenticated attackers to execute arbitrary Java code on vulnerable servers when Spring MVC applications are misconfigured (e.g., running on Tomcat/Jetty). It has historically posed a major risk to Java-based web applications and driven widespread patching and mitigations. The provided article, however, discusses a critical React vulnerability (CVE-2025-55182) and Cloudflare's remediation, not Spring4Shell.
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
On March 30, 2022, a zero-day remote code execution vulnerability in the Spring Framework, dubbed 'Spring4Shell' and assigned CVE-2022-22965, was disclosed. This vulnerability affects Spring MVC and Spring WebFlux…
The Spring4Shell vulnerability, affecting certain Spring-based Java applications, was disclosed on July 16, 2026. This exploit allows attackers to write malicious payloads to disk under specific conditions, including…
A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…
Spring4Shell is a high-severity remote code execution vulnerability in the Spring Framework (notably CVE-2022-22965) that can allow unauthenticated attackers to execute arbitrary Java code on vulnerable servers when Spring MVC applications are misconfigured (e.g., running on Tomcat/Jetty).
The most recent intelligence report mentioning Spring4Shell on ThreatCluster is dated July 24, 2026. Activity was first observed December 3, 2025, giving a tracked span from then to July 24, 2026.
Across ThreatCluster reporting, Spring4Shell most frequently co-occurs with Remote Code Execution, Sql Injection, Zero-day Exploit, CVE-2014-0224, CVE-2015-0204, among 12 tracked related entities.
The most significant recent cluster is “Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign” (59 articles · Updated July 23, 2026). Spring4Shell appears across 4 threat clusters in total, listed above with sources.
Spring4Shell appears in 5 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.