CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-40992

mediumCVSS 5covered by 2 sourcesfirst seen 2026-06-11
An attacker from an adjacent network can exploit multiple vulnerabilities in VMware Tanzu Spring Boot to bypass security measures, disclose and manipulate information, or potentially execute code.

CSIRTS triage

What
Multiple vulnerabilities in Tanzu Spring Boot allow security bypass, information disclosure, manipulation, and potential code execution.
Who is affected
Users of VMware Tanzu Spring Boot on adjacent networks are affected.
Urgency
Medium priority; local network access required for exploitation.
Action
Apply patches for CVE-2026-40992 and CVE-2026-41001.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-40992

Get an email if CVE-2026-40992 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-40992

CVE.org record

Embed the live status

CVE-2026-40992 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-40992 status](https://www.csirts.com/badge/CVE-2026-40992)](https://www.csirts.com/cve/CVE-2026-40992)