[UPDATE] [high] VMware Tanzu Spring Framework: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in VMware Tanzu Spring Framework to escalate privileges, execute arbitrary code, disclose sensitive information, bypass security measures, manipulate data, conduct cross-site scripting and open redirect attacks, or cause a denial-of-service condition.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to escalate privileges, execute arbitrary code, disclose sensitive information, and conduct various attacks.
- Who is affected
- Users of VMware Tanzu Spring Framework are affected.
- Urgency
- Remediation is high urgency due to the potential for severe exploitation and multiple attack vectors.
- Action
- Upgrade to the latest version of VMware Tanzu Spring Framework to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Tanzu Spring Framework
Get an email when a new Tanzu Spring Framework advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1828
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-418380.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-418390.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all scored CVEs.
- Low exploitation riskCVE-2026-418400.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-418410.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-418420.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-418430.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-418440.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-418450.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-418460.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all scored CVEs.
- Low exploitation riskCVE-2026-418470.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- high[NEW] [high] Oracle Utilities Applications: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Retail Applications: Multiple vulnerabilitiescert-bund
- mediumGHSA-wxpp-56q6-5pcg: Spring Framework Denial of Service via Unbounded Cache in SpELghsa
- mediumGHSA-957g-f97v-vppc: Spring Framework Cross-site Scripting via JSP Form Tagsghsa
- lowGHSA-659m-px2c-25wj: Spring Framework Denial of Service via AntPathMatcherghsa
- lowGHSA-9f52-rjqv-25qv: Spring Framework Arbitrary Method Invocation in SpEL Expressionsghsa
- highGHSA-775g-4xr8-78h8: Spring Framework Denial of Service via Integer Overflow in SpEL Expressionsghsa
- highGHSA-r5w3-xv2f-j59q: Spring Framework Algorithmic Denial of Service via SpEL Expressionsghsa
- mediumGHSA-vqgp-pf68-6947: Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSLghsa
- mediumGHSA-cjpg-rgq5-fr37: Spring Framework Multipart Request Smuggling in Spring MVC and WebFluxghsa
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31