CVE-2026-22732Disclosure(vmware / spring_security)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vmware spring_security systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-425

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_security

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 22 mentions across 13 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 17 signals
  • Disclosure: 12 classified signals
  • General: 4 classified signals
  • Peaked 12d ago at 4 mentions (2026-03-19); latest day: 1
  • 22 total mentions across 13 days

Affected systems

Vendors
Products
spring_security

Deep dive

Activity timeline22 mentions / 13d
01234Mentions · 2026-03-19: 4Mentions · 2026-03-20: 4Mentions · 2026-03-21: 1Mentions · 2026-03-23: 2Mentions · 2026-05-01: 2Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Mentions · 2026-05-15: 1Mentions · 2026-06-01: 1Mentions · 2026-06-09: 2Mentions · 2026-06-13: 1Mentions · 2026-07-01: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-05-01: 1PoC Mentioned / Linked · 2026-05-05: 1PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-09-11: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-06-09: 2Patch / Workaround · 2026-06-13: 1Technical Details · 2026-03-19: 4Technical Details · 2026-03-20: 3Technical Details · 2026-03-21: 1Technical Details · 2026-05-01: 2Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-09: 1Technical Details · 2026-06-13: 1Technical Details · 2026-07-01: 1Technical Details · 2026-09-11: 103-1903-2003-2103-2305-0105-0505-0605-1506-0106-0906-1307-0109-11
Signal classification4 categories
Disclosure
1254.5%
Patch
522.7%
General
418.2%
Exploit
14.5%
Referenced assets21 URLs
Classification over time
DateTotalLabels
2026-03-194
Disclosure4
2026-03-204
Disclosure1General1Patch2
2026-03-211
Disclosure1
2026-03-232
General2
2026-05-012
Disclosure2
2026-05-051
Patch1
2026-05-061
Disclosure1
2026-05-151
Disclosure1
2026-06-011
Disclosure1
2026-06-092
Disclosure1Patch1
2026-06-131
Patch1
2026-07-011
General1
2026-09-111
Exploit1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.1 CVSS flaw in Spring Security (CVE-2026-22732) fails to write HTTP headers, exposing Java apps to severe data leaks. Update immediately. #SpringSecurity #CVE202622732 #CyberSecurity #JavaSecurity #InfoSec #Vulnerability #DataLeak #AppSec https://securityonline.info/critical-spring-security-vulnerability-missing-http-headers-cve-2026-22732/ https://t.co/q0537PvKPA

    Post summary

    The tweet highlights the CVE-2026-22732 as a critical flaw with a CVSS score of 9.1 that can lead to severe data leaks due to missing HTTP headers, and it urges users to update immediately.

    090174710
    10.7K followersView on X
  • JFrog Security@JFrogSecurity
    Disclosure

    🚨 CVE-2026-22732 - new critical CVE in spring-security. Under certain configurations of spring security, HTTP security headers are not written. Not in NVD yet, but fixes are published. Update spring-security-web to 6.5.9 or 7.0.4 https://spring.io/security/cve-2026-22732

    Post summary

    A new critical CVE-2026-22732 in spring‑security has been disclosed. Fixes are available—upgrade spring‑security‑web to 6.5.9 or 7.0.4; no active exploitation or PoC has been reported.

    02053645
    3.2K followersView on X
  • OpenRewrite by Moderne@OpenRewrite
    Patch

    CVE-2026-22732: a 9.1 critical vulnerability in Spring Security that silently drops your security headers. No error. No log. Just gone. We had detection + remediation running in under a day—whole-perimeter coverage. This is what zero-day defense looks like. 🛡️ Here's how: http://buff.ly/jOo4I25

    Post summary

    A critical Spring Security flaw (CVE‑2026‑22732) that removes security headers was quickly detected and remediated within a day, with a link providing additional details on the fix.

    00021202
    1.2K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-22733 ❗ CVE-2026-22732 ❗ CVE-2026-22731 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-2/ https://t.co/p95JH7QS4Y

    Post summary

    The tweet notes three Spring product CVEs and directs readers to a link for additional information, without providing further technical or exploit details.

    01011108
    6.6K followersView on X
  • Steve Poole@spoole167
    General

    Your Spring Security headers may be silently missing. Here is how to check: https://www.herodevs.com/blog-posts/developer-docs-check-for-exposure-to-cve-2026-22732 @herodevs

    Post summary

    The tweet references CVE‑2026‑22732 and directs readers to a blog post about checking for missing Spring Security headers, but provides no concrete exploit details, patches, or evidence of active exploitation.

    00021101
    1.4K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #SAP has released security updates for 15 vulnerabilities in several of their products, including 4 critical vulnerabilities: #CVE-2026-44748; #CVE-2026-27671; #CVE-2026-40128 and #CVE-2026-22732. Read our advisory here: https://ccb.belgium.be/advisories/warning-sap-addresses-critical-vulnerabilities-affecting-multiple-sap-products-patch #Patch #Patch #Patch

    Post summary

    SAP has released patches for 15 vulnerabilities, including 4 critical CVEs, and provides an advisory link for more details.

    02000141
    7.2K followersView on X
  • Moderne, Inc.@moderneinc
    Disclosure

    CVE-2026-22732: a 9.1 critical vulnerability in Spring Security that silently drops your security headers. No error. No log. Just gone. We had detection + remediation running in under a day. Whole-perimeter coverage. This is what zero-day defense looks like. 🛡️ Here's how: https://buff.ly/tZ9kG9Z

    Post summary

    The post discloses a critical Spring Security vulnerability that silently removes security headers, highlights rapid detection and remediation, but lacks concrete exploit code or proof of active exploitation.

    10010161
    569 followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Disclosure

    🚨 NEW: SAP June Patch Day — 4 critical flaws, top CVSS 9.9. The worst: CVE-2026-44748 lets a low-privileged user forge SAML assertions and bypass authentication entirely on NetWeaver ABAP. CVE-2026-27671 (CVSS 9.8) is unauthenticated memory corruption via crafted RFC requests — potential RCE with no workaround, kernel update required. Also critical: CVE-2026-40128 (CVSS 9.0) unauthenticated directory traversal on NetWeaver Java, and CVE-2026-22732 (CVSS 9.1) unauthenticated Spring Security bypass in Commerce Cloud. SAP runs the back-end of most of the world's largest enterprises. No in-the-wild exploitation confirmed yet — patch now before that changes. Full breakdown 👇 https://www.bleepingcomputer.com/news/security/sap-fixes-critical-flaws-in-netweaver-and-commerce-cloud/

    Post summary

    SAP announced a June patch for four critical CVEs, providing detailed vulnerability descriptions and urging immediate patching, but no evidence of in‑the‑wild exploitation or a PoC/exploit code is presented.

    1000084
    77 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Atlassian ❗ CVE-2026-29145 ❗ CVE-2026-22732 ❗ CVE-2026-22029 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-atlassian-3/ https://t.co/OQ4O0L0bCR

    Post summary

    The tweet merely announces three Atlassian CVEs and directs readers to external links for details, without providing further technical or exploit information.

    00010105
    6.7K followersView on X
  • cybrmonk@cybr_monk
    Exploit

    Spring Security Header Bypass CVE-2026-22732: Exploit Code Now Live on GitHub https://cybrmonk.com/blog/spring-security-header-bypass-cve-2026-22732-exploit-code-now-live-on-github #cybersecurity #threatintelligence https://t.co/nRnNR2cADt

    Post summary

    Exploit code for CVE-2026-22732 has been released on GitHub, providing a publicly available PoC/exploit, but there is no evidence of live attacks or mitigation guidance.

    0000039
    47 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-22732: Spring Security HTTP Headers Omission - What It Means for Your Business and How to Respond https://hubs.li/Q04ndzbs0

    Post summary

    The text only titles the vulnerability with minimal technical detail and offers no actionable PoC, exploit, or mitigation information.

    0000030
    31 followersView on X
  • Secure Zona@securezona
    Patch

    The critical SAP Commerce Cloud vulnerability (CVE-2026-22732) shows how a simple Spring Security misconfiguration lets attackers bypass authentication completely. SecureZona fixes hardening gaps: Continuous cloud asset discovery Priorities config drift in unified risk queues

    Post summary

    The post points out a Spring Security misconfiguration in SAP Commerce Cloud (CVE‑2026‑22732) that bypasses authentication, and offers hardening fixes from SecureZona.

    0000076
    7.6K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-22732 | VMware Spring Security up to 7.0.3 HTTP Response Header direct request (WID-SEC-2026-0797) https://ift.tt/hcesM3t A vulnerability has been found in VMware Spring Security up to 7.0.3 and classified as critical. The impacted element is an unknown function of th…

    Post summary

    A critical vulnerability (CVE-2026-22732) affecting VMware Spring Security up to version 7.0.3 has been identified, with limited technical detail but no PoC or exploitation evidence presented.

    0000054
    974 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Disclosure

    TRC analysis shows CVE-2026-22732 exploits in Spring Security applications bypass critical HTTP response headers, enabling XSS and clickjacking attacks. Attackers escalate privileges through misconfigurations then move laterally to access other vulnerable services. Runtime segmentation helps contain post-compromise activity across affected environments. #Vulnerability #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/spring-security-cve-2026-22732-vulnerability-march-2026

    Post summary

    The TRC report explains that CVE‑2026‑22732 permits Spring Security applications to bypass key HTTP response headers, leading to XSS, clickjacking, privilege escalation and lateral movement, but no PoC, exploit, patch, or active exploitation is mentioned.

    0000050
    1.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    @moderneinc A silent killer: CVE-2026-22732 can drop security headers without a trace — avg dwell time for undetected breaches is 207 days. Zero-day defense must be proactive. http://research.lyrie.ai/streams/cve-2026-22732

    Post summary

    The tweet announces CVE‑2026‑22732, noting that it allows attackers to remove security headers for long undetected dwell times, but it provides no PoC, exploit code, or patch information.

    0000061
    152 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical vulnerability in `Spring Security` (CVE-2026-22732) may cause HTTP security headers to be omitted under certain conditions, impacting client-side protections. #SpringSecurity #infosec #websecurity https://www.pulsepatch.io/posts/cve-2026-22732-spring-security-http-headers-omitted

    Post summary

    The tweet highlights a newly disclosed Spring Security vulnerability that can strip HTTP security headers, emphasizing the potential risk without offering fixes or exploit details.

    0000069
    2 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical HTTP Security Headers Bypass in #SpringSecurity. #CVE-2026-22732 CVSS: 9.1. Servlet apps may silently drop all configured HTTP security headers exposing users to XSS, clickjacking & more. https://ccb.belgium.be/advisories/warning-multiple-types-client-side-attacks-spring-security-patch-immediately #Patch #Patch #Patch

    Post summary

    SpringSecurity CVE-2026-22732 enables bypass of HTTP security headers, exposing apps to XSS and clickjacking; a patch is strongly recommended.

    00000226
    7.2K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-22732 When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  T… https://www.cve.org/CVERecord?id=CVE-2026-22732 ----- Traducción: CVE-2026-22732 Cua… http://infoflow.cloud`

    Post summary

    The post merely references CVE-2026-22732 and provides a brief, non‑technical summary that HTTP headers may not be written in Spring Security servlet applications, with no further details on exploitation or mitigation.

    0000057
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22732 When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  T… https://www.cve.org/CVERecord?id=CVE-2026-22732

    Post summary

    The entry reports a new CVE (CVE-2026-22732) affecting Spring Security servlet applications by potentially omitting HTTP headers; no PoC, exploit, patch, or false‑positive claim is present.

    00000168
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-22732 - Critical When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Sp... https://www.thehackerwire.com/vulnerability/CVE-2026-22732/ https://t.co/2RnMDU2GAS

    Post summary

    The text announces a critical vulnerability (CVE-2026-22732) affecting Spring Security, describing how HTTP headers may not be written, but it does not provide PoC, exploit details, or evidence of active exploitation. No patch or workaround is mentioned.

    0000062
    137 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_security---

Explore more