Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.4VMware Updated

High [CVE-2026-41707] Spring Security: Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwt…

Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. This issue affects Spring Security: 7.1.0, from 7.0.0 through 7.0.6, and from 6.5.0 through 6.5.11.

CVE-2026-41707
Tanzu / Spring
Aug 25, 2026
High7.5VMware

High [CVE-2026-47827] BOSH: Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell co…

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities

CVE-2026-47827
Tanzu / Spring
Aug 21, 2026
Critical9.3VMware

Critical [CVE-2026-47876] VMXNET3 out-of-bounds write vulnerability

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.

CVE-2026-47876
ESXiCloud FoundationvSphere
Jul 30, 2026
Critical9.8VMware

Critical [CVE-2026-59309] vCenter: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Infrastructure; Telco Cloud Platform.

CVE-2026-59309
ESXivCenterCloud FoundationvSphere
Jul 30, 2026
Critical9.8VMware Exploited CISA KEV

Critical [CVE-2026-59310] vCenter: VMware vCenter contains a directory traversal vulnerability in the Syslog server.

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Infrastructure; Telco Cloud Platform.

CVE-2026-59310
ESXivCenterCloud FoundationvSphere
Jul 30, 2026
High7.6VMware

High [CVE-2026-41703] Out-of-bounds read vulnerability

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.

CVE-2026-41703
ESXiCloud FoundationWorkstation & FusionvSphere
Jul 30, 2026
High8.3VMware

High [CVE-2026-47882] Spring Boot: When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud F…

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-47882
Tanzu / Spring
Jul 30, 2026
High8.0VMware

High [CVE-2026-47858] Spring Boot: Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applic…

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-47858
Tanzu / Spring
Jul 30, 2026
Critical9.8VMware

Critical [CVE-2026-47865] Avi Load Balancer: VMware Avi Load Balancer contains an authentication bypass vulnerability.

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.

CVE-2026-47865
Avi / VeloCloud
Jul 18, 2026
High8.8VMware

High [CVE-2026-47871] Avi Load Balancer: VMware Avi Load Balancer contains a directory traversal vulnerability.

VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks.

CVE-2026-47871
Avi / VeloCloud
Jul 18, 2026
High7.1VMware

High [CVE-2026-47870] Avi Load Balancer: VMware Avi Load Balancer contains a privilege escalation vulnerability.

VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code.

CVE-2026-47870
Avi / VeloCloud
Jul 18, 2026
High8.7VMware

High [CVE-2026-47869] Avi Load Balancer: VMware Avi Load Balancer contains a remote code execution vulnerability.

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.

CVE-2026-47869
Avi / VeloCloud
Jul 18, 2026
High7.8VMware

High [CVE-2026-47868] Avi Load Balancer: VMware Avi Load Balancer contains a local privilege escalation vulnerability.

VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root.

CVE-2026-47868
Avi / VeloCloud
Jul 18, 2026
High8.7VMware

High [CVE-2026-47867] Avi Load Balancer: VMware Avi Load Balancer contains a remote code execution vulnerability.

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely.

CVE-2026-47867
Avi / VeloCloud
Jul 18, 2026
High8.3VMware

High [CVE-2026-47866] Avi Load Balancer: VMware Avi Load Balancer contains an authorization bypass vulnerability.

VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.

CVE-2026-47866
Avi / VeloCloud
Jul 18, 2026
Critical9.6VMware

Critical [CVE-2026-22752] Spring Security: Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.

CVE-2026-22752
Tanzu / Spring
Jul 16, 2026
Critical9.1VMware

Critical [CVE-2026-47826] BOSH: The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and e…

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

CVE-2026-47826
Tanzu / Spring
Jul 9, 2026
High7.5VMware

High [CVE-2026-47840] network attacker positioned between UAA and its LDAP directory

A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.

CVE-2026-47840
Unclassified
Jul 9, 2026
High7.5VMware

High [CVE-2026-47831] BOSH: Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemce…

Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.

CVE-2026-47831
Tanzu / Spring
Jul 9, 2026
High8.8VMware

High [CVE-2026-47830] BOSH: Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privile…

Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.

CVE-2026-47830
Tanzu / Spring
Jul 9, 2026