ThreatCluster[verified]@threatclusterDisclosure
Spring Framework discloses three new CVEs that enable RCE, session hijack, and unauthorized endpoint access, and urges users to upgrade immediately.
CCB Alert@CCBalertPatch
The advisory warns of high‑severity Spring Boot weaknesses and urges immediate patching, but includes no proof of exploitation or PoC.
CVE@CVEnewDisclosure
The post cites CVE-2026-40972, noting an attacker can perform a timing attack to learn a remote secret, but offers no PoC, exploit code, or patch details.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026-40972, describing a timing-based information disclosure threat on a local network; it provides no PoC, exploit code, patch, or evidence of active exploitation.
CERT-PY@CERTpyDisclosure
The post announces three CVE vulnerabilities in Spring products and provides a link for further information, without disclosing PoC, exploit code, patches, or evidence of active exploitation.
CVEarity@CVEarityDisclosure
The tweet announces the new CVE‑2026‑40972 with a severity score of 7.5, but offers no technical, exploit, or mitigation details.