Skip to content
Signals
NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · vmware

vmware

· 86 Critical

Total CVEs

984

Critical

86

Products

194

Search All CVEs →

984

Products (194)

workstation217 CVEsesxi139 CVEscloud foundation133 CVEsfusion131 CVEsplayer89 CVEsesx86 CVEsvcenter server79 CVEsvsphere61 CVEsserver59 CVEsspring framework56 CVEsace44 CVEsspring security32 CVEsidentity manager28 CVEsworkstation pro27 CVEsworkstation player26 CVEshorizon client25 CVEstools22 CVEsvrealize suite lifecycle manager21 CVEsvrealize automation20 CVEsspring boot19 CVEsvrealize operations18 CVEsvmware workstation15 CVEsworkspace one access15 CVEsvrealize log insight15 CVEshorizon view14 CVEsvcenter server appliance14 CVEsspring ai14 CVEsaria operations13 CVEsidentity manager connector13 CVEstelco cloud platform11 CVEsone access11 CVEsvirtualcenter10 CVEstelco cloud infrastructure10 CVEsaccess connector9 CVEsvmware server9 CVEsvsphere data protection8 CVEsaria operations for networks8 CVEsvrealize operations manager8 CVEsesx server8 CVEsspring cloud config8 CVEsaria operations for logs8 CVEsvma7 CVEsview7 CVEsremote console6 CVEsmovie decoder6 CVEshorizon view client6 CVEssd-wan orchestrator6 CVEsrabbitmq6 CVEsgsx server6 CVEsphoton os6 CVEshorizon6 CVEsvcenter5 CVEsfusion pro5 CVEsvcloud director5 CVEsopen vm tools5 CVEsworkspace one assist5 CVEsvmware player5 CVEsairwatch4 CVEsspring advanced message queuing protocol4 CVEsvsphere client4 CVEshorizon daas4 CVEsspring for graphql4 CVEscarbon black app control4 CVEsspringsource spring security4 CVEsspring hateoas3 CVEsspring cloud gateway3 CVEsspring integration zip3 CVEsixgben3 CVEsaria automation3 CVEsvrealize orchestrator3 CVEsvrealize network insight3 CVEssingle sign-on for pivotal cloud foundry3 CVEsstudio3 CVEsinstallbuilder3 CVEscloud director3 CVEsairwatch agent3 CVEsvmware hcx2 CVEsvmware esx2 CVEsvmware esxi2 CVEsopen-vm-tools2 CVEsvm-support2 CVEsairwatch inbox2 CVEsvix api2 CVEspinniped2 CVEsvirtual infrastructure client2 CVEshyperic server2 CVEsvsphere esxi2 CVEsnsx edge2 CVEsnsx data center2 CVEsairwatch console2 CVEsworkspace one boxer2 CVEsworkspace one content2 CVEsrabbitmq java client2 CVEshyperic hq2 CVEsworkspace one uem console2 CVEsace 22 CVEsaccess2 CVEsvcenter orchestrator2 CVEsgemfire2 CVEsspring cloud data flow2 CVEsspring cloud function2 CVEsspring cloud netflix2 CVEsapp volumes2 CVEsapplication remote collector2 CVEsinfrastructure2 CVEsspring data rest2 CVEsvcenter chargeback manager2 CVEsspring grpc2 CVEsspring integration2 CVEstc server2 CVEstanzu gemfire for virtual machines2 CVEstanzu application service for virtual machines2 CVEsvmware player 22 CVEszimbra desktop1 CVEsairwatch launcher1 CVEsams1 CVEsbosh editor1 CVEscapacityiq1 CVEscarbon black cloud1 CVEscarbon black cloud workload1 CVEscloud foundation operations1 CVEscloudfoundry manifest yml support1 CVEsconcourse ci pipeline editor1 CVEsgreenplum database1 CVEsharbor container registry1 CVEshorizon view agent1 CVEshorizon view agents1 CVEshyperic agent1 CVEsi40en1 CVEsintelligent hub1 CVEsisolation segment1 CVEslab manager1 CVEsnsx1 CVEsnsx-v edge1 CVEsnsx sd-wan by velocloud1 CVEsoperations manager1 CVEsovf tool1 CVEspivotal scheduler1 CVEspivotal software mysql1 CVEssd-wan by velocloud1 CVEssd-wan edge1 CVEssd-wan edge firmware1 CVEssingle sign-on for tanzu1 CVEsspring boot tools1 CVEsspring cloud contract1 CVEsspring cloud netflix zuul1 CVEsspring cloud openfeign1 CVEsspring cloud sso connector1 CVEsspring cloud task1 CVEsspring cloud vault1 CVEsspring data mongodb1 CVEsspring for apache kafka1 CVEsspring session1 CVEsspring social1 CVEsspring tools1 CVEsspring vault1 CVEsstage manager1 CVEstanzu application service for vms1 CVEsthinapp1 CVEsunified access gateway1 CVEsvcenter lab manager1 CVEsvcenter operations1 CVEsvcenter stage manager1 CVEsvcenter update manager1 CVEsvcloud automation center1 CVEsvcloud automation identity appliance1 CVEsvcloud networking and security1 CVEsvcloud networking and security edge1 CVEsvelero1 CVEsvi-client1 CVEsview manager1 CVEsview planner1 CVEsvmware ace1 CVEsvmware virtualcenter1 CVEsvrealize business advanced and enterprise1 CVEsvrealize business for cloud1 CVEsvrealize operations for horizon1 CVEsvrealize operations for published applications1 CVEsvrealize operations tenant1 CVEsvshield manager1 CVEsvsphere integrated containers1 CVEsvsphere replication1 CVEsworkspace one1 CVEsworkspace one intelligent hub1 CVEsworkspace one launcher1 CVEsworkspace one notebook1 CVEsworkspace one people1 CVEsworkspace one piv-d manager1 CVEsworkspace one sdk1 CVEsworkspace one sdk \(objective-c\)1 CVEsworkspace one uem1 CVEsworkspace one unified endpoint management1 CVEsworkspace one web1 CVEsxenon1 CVEs

Recent Vulnerabilities

View all 984
CVE-2026-41856HIGH 7.5

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.

CVE-2026-41700HIGH 8.1

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.

CVE-2026-41699HIGH 8.1

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be leveraged during deserialization. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8.

CVE-2026-41694LOW 3.7

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-41003HIGH 7.6

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-40988HIGH 7.5

An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-41852LOW 3.7

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41848LOW 3.7

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41847MEDIUM 4.8

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVE-2026-41846MEDIUM 5.9

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41845HIGH 7.1

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41844MEDIUM 4.2

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41838MEDIUM 4.8

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41007HIGH 7.5

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

CVE-2026-41006HIGH 7.5

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

CVE-2026-41702HIGH 7.8

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.

CVE-2026-41713HIGH 8.2

A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.

CVE-2026-41712HIGH 7.5

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.

CVE-2026-41705HIGH 8.6

Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 through latest 1.1.x; upgrade to 1.1.6 or greater.

CVE-2026-41004MEDIUM 4.4

When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

CVE-2026-41002HIGH 7.2

The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

CVE-2026-40982CRITICAL 9.1

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

CVE-2026-40981HIGH 7.5

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

CVE-2026-22745MEDIUM 5.3

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.

CVE-2026-22741LOW 3.1

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.