Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

11 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8VMware Updated

Critical [CVE-2026-59313] Spring Framework: Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent…

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Affected product named by the advisory: Spring Framework.

CVE-2026-59313
Tanzu / Spring
Aug 27, 2026
Critical9.1VMware Updated

Critical [CVE-2026-59283] Spring Framework: Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnera…

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8

CVE-2026-59283
Tanzu / Spring
Aug 27, 2026
Critical9.6VMware Updated

Critical [CVE-2026-59354] Spring Security: In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registra…

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may result in Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF). Affected product named by the advisory: Spring Security (OAuth2 Authorization Server module).

CVE-2026-59354
Tanzu / Spring
Aug 27, 2026
Critical9.8VMware Updated

Critical [CVE-2026-47892] Spring Framework: WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header pr…

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47892
Tanzu / Spring
Aug 27, 2026
Critical9.8VMware Updated

Critical [CVE-2026-47891] Spring Framework: Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the…

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47891
Tanzu / Spring
Aug 27, 2026
Critical9.8VMware Updated

Critical [CVE-2026-47890] Spring Framework: Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view…

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47890
Tanzu / Spring
Aug 27, 2026
Critical9.8VMware Updated

Critical [CVE-2026-47884] Spring Framework: Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping…

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47884
Tanzu / Spring
Aug 27, 2026
Critical9.4VMware Updated

Critical [CVE-2026-59270] Spring Security: Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative cre…

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.

CVE-2026-59270
Tanzu / Spring
Aug 27, 2026
Critical9.3VMware

Critical [CVE-2026-47876] VMXNET3 out-of-bounds write vulnerability

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.

CVE-2026-47876
ESXiCloud FoundationvSphere
Jul 30, 2026
Critical9.8VMware

Critical [CVE-2026-59309] vCenter: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Infrastructure; Telco Cloud Platform.

CVE-2026-59309
ESXivCenterCloud FoundationvSphere
Jul 30, 2026
Critical9.8VMware Exploited CISA KEV

Critical [CVE-2026-59310] vCenter: VMware vCenter contains a directory traversal vulnerability in the Syslog server.

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Infrastructure; Telco Cloud Platform.

CVE-2026-59310
ESXivCenterCloud FoundationvSphere
Jul 30, 2026