CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-41001

mediumCVSS 5.3covered by 2 sourcesfirst seen 2026-06-11
An attacker from an adjacent network can exploit multiple vulnerabilities in VMware Tanzu Spring Boot to bypass security measures, disclose and manipulate information, or potentially execute code.

CSIRTS triage

What
Multiple vulnerabilities in Tanzu Spring Boot allow security bypass, information disclosure, manipulation, and potential code execution.
Who is affected
Users of VMware Tanzu Spring Boot on adjacent networks are affected.
Urgency
Medium priority; local network access required for exploitation.
Action
Apply patches for CVE-2026-40992 and CVE-2026-41001.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-41001

Get an email if CVE-2026-41001 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-41001

CVE.org record

Embed the live status

CVE-2026-41001 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-41001 status](https://www.csirts.com/badge/CVE-2026-41001)](https://www.csirts.com/cve/CVE-2026-41001)