CVE-2022-22965General(cisco / access_appliance)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch cisco access_appliance systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

6.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-04-25. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-94

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • access_appliance
  • commerce_platform
  • communications_cloud_native_core_automated_test_suite
  • communications_cloud_native_core_binding_support_function

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 12 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 5 classified signals
  • Peaked 9d ago at 2 mentions (2026-03-09); latest day: 1
  • 14 total mentions across 12 days

Affected systems

Products
access_appliancecommerce_platformcommunications_cloud_native_core_automated_test_suitecommunications_cloud_native_core_binding_support_functioncommunications_cloud_native_core_consolecommunications_cloud_native_core_network_exposure_functioncommunications_cloud_native_core_network_function_cloud_native_environmentcommunications_cloud_native_core_network_repository_functioncommunications_cloud_native_core_network_slice_selection_functioncommunications_cloud_native_core_policy

48 versions affected across 39 products

Deep dive

Activity timeline14 mentions / 12d
01122Mentions · 2026-02-19: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 2Mentions · 2026-03-18: 2Mentions · 2026-03-29: 1Mentions · 2026-04-03: 1Mentions · 2026-04-15: 1Mentions · 2026-04-28: 1Mentions · 2026-05-02: 1Mentions · 2026-06-17: 1Mentions · 2026-06-21: 1Mentions · 2026-07-08: 1PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-04-03: 1PoC Mentioned / Linked · 2026-05-02: 1PoC Mentioned / Linked · 2026-06-17: 1PoC Mentioned / Linked · 2026-07-08: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-06-17: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-06-21: 1Technical Details · 2026-03-18: 1Technical Details · 2026-05-02: 1Technical Details · 2026-06-17: 1Technical Details · 2026-06-21: 102-1903-0803-0903-1803-2904-0304-1504-2805-0206-1706-2107-08
Signal classification5 categories
General
535.7%
PoC
428.6%
Active Exploitation
321.4%
Exploit
17.1%
Patch
17.1%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-191
General1
2026-03-081
General1
2026-03-092
Active Exploitation1PoC1
2026-03-182
Exploit1General1
2026-03-291
General1
2026-04-031
PoC1
2026-04-151
Active Exploitation1
2026-04-281
General1
2026-05-021
PoC1
2026-06-171
Active Exploitation1
2026-06-211
Patch1
2026-07-081
PoC1
Full discourse14 posts
  • Vivek | Cybersecurity@VivekIntel
    General

    wolf-tools — Threat Intel + Detection Rules Pack 🐺⚡ • Vulnerability Scanners Log4Shell Deep Scan (CVE-2021-44228, 45046) Spring4Shell Deep Scan (CVE-2022-22965) • Threat Intelligence YARA, Sigma, Suricata rules + IOCs • Ransomware Coverage Lorenz ransomware artifacts + detection rules • Exploitation Detection CVE-2023-22527 (Confluence → C3RB3R ransomware) • Defense Controls WDAC policy for blocking dual-use app abuse Focused on real detection + hunting, not theory. 🔗 https://github.com/rtkwlf/wolf-tools #ThreatIntel #SOC #BlueTeam #CyberSecurity #DetectionEngineering

    Post summary

    The post advertises a detection and threat‑intel toolset, noting CVEs and mitigation measures, but lacks PoC, exploit code, or evidence of active exploitation.

    06024251.8K
    16.1K followersView on X
  • RootEvil333@RootEvil333
    PoC

    Hey, world 🤙 I just released a few projects on GitHub: - Two PoCs for #CVE-2022-22965 and #CVE-2025-55182, written in C and Go. - A simple C# project demonstrating how AES encryption works. GitHub: https://github.com/RootEvil333 More CVE exploit are coming, stay tuned Peace, ✌️ https://t.co/csChjOj0Pe

    Post summary

    The author announces that they have released Proof‑of‑Concept code for CVE‑2022‑22965 and CVE‑2025‑55182 on GitHub and hints at additional CVE exploits to follow.

    00010109
    3 followersView on X
  • 無重力トレーニング@acupunc28094787
    PoC

    I just completed Spring4Shell: CVE-2022-22965 room on TryHackMe! Interactive lab for exploiting Spring4Shell (CVE-2022-22965) in the Java Spring Framework https://tryhackme.com/room/spring4shell?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=65869e2abbbd1398b6caad7d #tryhackme via @tryhackme

    Post summary

    The user completed and shared a TryHackMe lab that demonstrates exploitation of Spring4Shell (CVE-2022-22965), providing an interactive proof of concept for the vulnerability.

    0001054
    96 followersView on X
  • Audn AI@audn_ai
    Exploit

    We built a scanner with nmap -sV on port 443, fed results into nuclei templates for CVE-2022-22965 (Spring4Shell) and uncovered a misconfigured Tomcat that let us drop a webshell in seconds. https://x.com/i/status/2033880735166153169

    Post summary

    The author used scanning tools to discover CVE-2022-22965 on a Tomcat server and successfully dropped a webshell, demonstrating the vulnerability can be exploited.

    0001062
    87 followersView on X
  • 🏴‍☠️ The Pirate 🏴‍☠️@Pinperepette
    General

    @super_caz @Napalm51 ma mica una... https://nvd.nist.gov/vuln/detail/CVE-2022-22965

    Post summary

    The tweet references CVE-2022-22965 via an NVD link but offers no additional details, evidence of exploitation, or mitigation information.

    00010347
    16.9K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Spring Framework RCE "Spring4Shell" (CVE-2022-22965) A Spring MVC or Spring WebFlux application running on JDK 9+ can be vulnerable to remote code execution through data binding. By crafting requests that manipulate object properties via Spring's data-binding mechanism (reaching ClassLoader-related fields), an attacker can write a malicious file such as a JSP web shell and execute arbitrary code. The classic exploit path requires the application to be deployed as a WAR on Apache Tomcat; Spring Boot executable jars in the default configuration are not affected, though the underlying weakness is more general. The flaw is remotely exploitable with no privileges or user interaction. 👉Upgrade to Spring Framework 5.3.18 or 5.2.20.

    Post summary

    The tweet reports the Spring Framework RCE (CVE‑2022‑22965), describes the exploitation mechanism, and provides the necessary framework versions for mitigation.

    00000104
    223 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    The zero-day CVE-2022-22965 'Spring4Shell' remote code execution flaw in Spring Framework (CVSS 9.8) is being exploited in the wild against Tomcat WAR deployments on JDK 9+, Rapid7 reported. https://threatcluster.io/cluster/spring-framework-rce-vulnerability-cve-2022-22965-exploited--8bf5fb45

    Post summary

    Spring4Shell (CVE-2022-22965) is a high‑severity RCE flaw in the Spring Framework that is actively being exploited in the wild against Tomcat WAR deployments on JDK 9+.

    0000078
    356 followersView on X
  • Audn AI@audn_ai
    Active Exploitation

    We saw our autonomous agent pivot from port 22 SSH on a misconfigured Cisco ASA, grab creds via Hydra, then chain into CVE-2022-22965 on Tomcat and exfil data. It showed orchestration beats manual grind 😊 https://x.com/i/status/2043396355260031340

    Post summary

    The tweet reports real‑world exploitation of CVE‑2022‑22965 by an autonomous agent pivoting from SSH into Tomcat and exfiltrating data.

    0000063
    144 followersView on X
  • Sun4lower@LittleSun4lower
    PoC

    I just completed Spring4Shell: CVE-2022-22965 room on TryHackMe! Interactive lab for exploiting Spring4Shell (CVE-2022-22965) in the Java Spring Framework https://tryhackme.com/room/spring4shell?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #learning

    Post summary

    The user completed a TryHackMe interactive lab that demonstrates exploitation of CVE-2022-22965 (Spring4Shell) in Java Spring, effectively sharing a PoC via the provided link.

    0000031
    5 followersView on X
  • Audn AI@audn_ai
    General

    We ran the AI scanner on https://x.com/i/status/2037007563435254090, ffuf fuzzed 12k endpoints in seconds, Nuclei confirmed CVE-2022-22965 in the admin portal. It showed AI can surface hidden gems, felt like a rush 🚀

    Post summary

    The post reports that an AI scanner, together with ffuf and Nuclei, detected CVE‑2022‑22965 in an admin portal, confirming the vulnerability’s presence.

    0000044
    127 followersView on X
  • PulseEinher@PulseEinher
    General

    Day 64/100 ✔ LeetCode: Two Sum https://leetcode.com/problems/two-sum/description/ ✔ TryHackMe: Spring4Shell: CVE-2022-22965 https://tryhackme.com/room/spring4shell/ ✔ Medium: broker CTF – Walkthrough (Updated) https://pulse-einher.medium.com/try-hack-me-broker-ctf-walkthrough-d131bd5a622b Continuing tomorrow. https://t.co/nqm8ftvZOJ

    Post summary

    The post merely lists CVE-2022-22965 and points to a TryHackMe training room, without additional technical detail or exploit information.

    0000030
  • 317ON13_LIRW@ToTo13ru_xakep
    PoC

    I just completed Spring4Shell: CVE-2022-22965 room on TryHackMe! Interactive lab for exploiting Spring4Shell (CVE-2022-22965) in the Java Spring Framework https://tryhackme.com/room/spring4shell?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet highlights that the author completed an interactive lab demonstrating exploitation of Spring4Shell (CVE-2022-22965), indicating the presence of a PoC environment, but provides no technical details, patches, or evidence of wild exploitation.

    0000019
  • Mike (BitFarmer) Chamberland@mercjr
    Active Exploitation

    🔴 Wall of Shame LIVE: Bots hammering honeypots! Top hits: - WordPress Exploitation (hundreds!) - Sensitive File Disclosure - CVE-2022-22965 attempts See cities like New Delhi & Vilnius pop up with masked IPs. Real threats only! https://www.youtube.com/watch?v=-h6-Velotiw #CyberSecurity #Honeypot #InfoSec

    Post summary

    Bots are actively attempting to exploit CVE-2022-22965 across multiple regions, targeting honeypots.

    0000096
    160 followersView on X
  • CVEDatabase.com@cvedatabase
    General

    CVE-2022-22965 (Spring4Shell) A reminder that: Framework bugs scale fast Defaults matter JVM apps age badly without maintenance This one didn’t need nation-state attackers—just exposed apps and bad timing. Details here: https://cvedatabase.com/cve/CVE-2022-22965 #Spring4Shell #CVEAlert

    Post summary

    A brief CVE alert reminding readers about Spring4Shell (CVE-2022-22965), noting that exposed applications are sufficient for exploitation, but providing no technical details or evidence of active attacks.

    0000027
    1 followersView on X
CPE platform detail89 entries

89 of 89 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocx_cloud_agent---
Apporaclecommerce_platform11.3.2--
Apporaclecommunications_cloud_native_core_automated_test_suite1.9.0--
Apporaclecommunications_cloud_native_core_automated_test_suite22.1.0--
Apporaclecommunications_cloud_native_core_binding_support_function22.1.3--
Apporaclecommunications_cloud_native_core_console1.9.0--
Apporaclecommunications_cloud_native_core_console22.1.0--
Apporaclecommunications_cloud_native_core_network_exposure_function22.1.0--
Apporaclecommunications_cloud_native_core_network_function_cloud_native_environment1.10.0--
Apporaclecommunications_cloud_native_core_network_function_cloud_native_environment22.1.0--
Apporaclecommunications_cloud_native_core_network_repository_function1.15.0--
Apporaclecommunications_cloud_native_core_network_repository_function22.1.0--
Apporaclecommunications_cloud_native_core_network_slice_selection_function1.15.0--
Apporaclecommunications_cloud_native_core_network_slice_selection_function1.8.0--
Apporaclecommunications_cloud_native_core_network_slice_selection_function22.1.0--
Apporaclecommunications_cloud_native_core_policy1.15.0--
Apporaclecommunications_cloud_native_core_policy22.1.0--
Apporaclecommunications_cloud_native_core_security_edge_protection_proxy1.7.0--
Apporaclecommunications_cloud_native_core_security_edge_protection_proxy22.1.0--
Apporaclecommunications_cloud_native_core_unified_data_repository1.15.0--
Apporaclecommunications_cloud_native_core_unified_data_repository22.1.0--
Apporaclecommunications_policy_management12.6.0.0.0--
Apporaclecommunications_unified_inventory_management7.4.1--
Apporaclecommunications_unified_inventory_management7.4.2--
Apporaclecommunications_unified_inventory_management7.5.0--
Apporaclefinancial_services_analytical_applications_infrastructure8.1.1--
Apporaclefinancial_services_analytical_applications_infrastructure8.1.2.0--
Apporaclefinancial_services_behavior_detection_platform8.1.1.0--
Apporaclefinancial_services_behavior_detection_platform8.1.1.1--
Apporaclefinancial_services_behavior_detection_platform8.1.2.0--
Apporaclefinancial_services_enterprise_case_management8.1.1.0--
Apporaclefinancial_services_enterprise_case_management8.1.1.1--
Apporaclefinancial_services_enterprise_case_management8.1.2.0--
Apporaclejdk---
Apporaclemysql_enterprise_monitor---
Apporacleproduct_lifecycle_analytics3.6.1--
Apporacleretail_bulk_data_integration16.0.3--
Apporacleretail_customer_management_and_segmentation_foundation17.0--
Apporacleretail_customer_management_and_segmentation_foundation18.0--
Apporacleretail_customer_management_and_segmentation_foundation19.0--
Apporacleretail_financial_integration14.1.3.2--
Apporacleretail_financial_integration15.0.3.1--
Apporacleretail_financial_integration16.0.3--
Apporacleretail_financial_integration19.0.1--
Apporacleretail_integration_bus14.1.3.2--
Apporacleretail_integration_bus15.0.3.1--
Apporacleretail_integration_bus16.0.3--
Apporacleretail_integration_bus19.0.1--
Apporacleretail_merchandising_system16.0.3--
Apporacleretail_merchandising_system19.0.1--
Apporacleretail_xstore_point_of_service20.0.1--
Apporacleretail_xstore_point_of_service21.0.0--
Apporaclesd-wan_edge9.0--
Apporaclesd-wan_edge9.1--
Apporacleweblogic_server12.2.1.3.0--
Apporacleweblogic_server12.2.1.4.0--
Apporacleweblogic_server14.1.1.0.0--
Appsiemensoperation_scheduler---
Appsiemenssimatic_speech_assistant_for_machines---
Appsiemenssinec_network_management_system---
Appsiemenssipass_integrated2.80--
Appsiemenssipass_integrated2.85--
Appsiemenssiveillance_identity1.5--
Appsiemenssiveillance_identity1.6--
Appveritasaccess_appliance7.4.3--
Appveritasaccess_appliance7.4.3.100--
Appveritasaccess_appliance7.4.3.200--
Appveritasflex_appliance1.3--
Appveritasflex_appliance2.0--
Appveritasflex_appliance2.0.1--
Appveritasflex_appliance2.0.2--
Appveritasflex_appliance2.1--
HWveritasnetbackup_appliance4.0--
HWveritasnetbackup_appliance4.0.0.1--
HWveritasnetbackup_appliance4.0.0.1--
HWveritasnetbackup_appliance4.0.0.1--
HWveritasnetbackup_appliance4.1--
HWveritasnetbackup_appliance4.1.0.1--
HWveritasnetbackup_appliance4.1.0.1--
Appveritasnetbackup_flex_scale_appliance2.1--
Appveritasnetbackup_flex_scale_appliance3.0--
HWveritasnetbackup_virtual_appliance4.0--
HWveritasnetbackup_virtual_appliance4.0.0.1--
HWveritasnetbackup_virtual_appliance4.0.0.1--
HWveritasnetbackup_virtual_appliance4.0.0.1--
HWveritasnetbackup_virtual_appliance4.1--
HWveritasnetbackup_virtual_appliance4.1.0.1--
HWveritasnetbackup_virtual_appliance4.1.0.1--
Appvmwarespring_framework---

Explore more