JFrog Security[verified]@JFrogSecurityDisclosure
A new critical CVE-2026-22732 in spring‑security has been disclosed. Fixes are available—upgrade spring‑security‑web to 6.5.9 or 7.0.4; no active exploitation or PoC has been reported.
OpenRewrite by Moderne[verified]@OpenRewritePatch
A critical Spring Security flaw (CVE‑2026‑22732) that removes security headers was quickly detected and remediated within a day, with a link providing additional details on the fix.
Moderne, Inc.[verified]@moderneincDisclosure
The post discloses a critical Spring Security vulnerability that silently removes security headers, highlights rapid detection and remediation, but lacks concrete exploit code or proof of active exploitation.
CyberAlertsHQ[verified]@CyberAlertsHQDisclosure
SAP announced a June patch for four critical CVEs, providing detailed vulnerability descriptions and urging immediate patching, but no evidence of in‑the‑wild exploitation or a PoC/exploit code is presented.
IntegSec[verified]@integ_secGeneral
The text only titles the vulnerability with minimal technical detail and offers no actionable PoC, exploit, or mitigation information.
Israel[verified]@f1tym1Disclosure
A critical vulnerability (CVE-2026-22732) affecting VMware Spring Security up to version 7.0.3 has been identified, with limited technical detail but no PoC or exploitation evidence presented.
Aviatrix Threat Research Center[verified]@aviatrixtrcDisclosure
The TRC report explains that CVE‑2026‑22732 permits Spring Security applications to bypass key HTTP response headers, leading to XSS, clickjacking, privilege escalation and lateral movement, but no PoC, exploit, patch, or active exploitation is mentioned.
Lyrie.ai[verified]@lyrie_aiDisclosure
The tweet announces CVE‑2026‑22732, noting that it allows attackers to remove security headers for long undetected dwell times, but it provides no PoC, exploit code, or patch information.