CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-40988

highCVSS 7.5covered by 2 sourcesfirst seen 2026-06-10
A remote, anonymous attacker can exploit multiple vulnerabilities in VMware Tanzu Spring Security to cause a Denial of Service, execute arbitrary code, redirect users to arbitrary websites, disclose information, and assume the identity of another user.

CSIRTS triage

What
Multiple vulnerabilities in Tanzu Spring Security allow denial of service, remote code execution, open redirect, information disclosure, and identity spoofing.
Who is affected
All users of VMware Tanzu Spring Security are affected.
Urgency
Medium priority; multiple attack vectors present including unauthenticated DoS and RCE despite medium rating.
Action
Apply patches for CVE-2026-40988, CVE-2026-40993, CVE-2026-41003, CVE-2026-41008, CVE-2026-41694, CVE-2026-41706, and CVE-2026-47838.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-40988

Get an email if CVE-2026-40988 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-40988

CVE.org record

Embed the live status

CVE-2026-40988 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-40988 status](https://www.csirts.com/badge/CVE-2026-40988)](https://www.csirts.com/cve/CVE-2026-40988)