CVE-2026-47873
Serial number: AV26-759 Date: July 30, 2026 As of July 30, 2026, Spring is affected by vulnerabilities in the following products: Spring Tools for Eclipse Prior to or equal to 5.2.0 Spring Tools for VSCode / Cursor / Theia Prior to or equal to 2.2.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-47858: live information startup mode is vulnerable for remote code execution CVE-2026-47873: Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces CVE-2026-47882: Spring Boot DevTools remote secret generated with a non-cryptographic PRNG CVE-2026-59326: HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server CVE-2026-59327: Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations CVE-2026-59328: Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips Spring | Security Advisories
CSIRTS triage
- What
- Multiple vulnerabilities exist, including one that allows for remote code execution.
- Who is affected
- Users of Spring Tools for Eclipse and Spring Tools for VSCode / Cursor / Theia prior to the specified versions are affected.
- Urgency
- Remediation is necessary, but the vulnerabilities are not actively exploited.
- Action
- Users should review and apply updates as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-47873
Get an email if CVE-2026-47873 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownSpring security advisory (AV26-759)cccs · 2026-07-30
- highCVE-2026-47873: The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all…nvd · 2026-07-30
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-47873)