logo

Spring Framework RCE Vulnerability CVE-2022-22965 Exploited in the Wild

ID: 652e54f3-7352-5ae0-b059-3f9be53a2226

STIX ID: report--652e54f3-7352-5ae0-b059-3f9be53a2226

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

...
...

On March 30, 2022 a zero-day remote code execution vulnerability in the Spring Framework (Spring4Shell, CVE-2022-22965) was disclosed. The flaw (CVSS 9.8) affects Spring MVC and Spring WebFlux apps running on JDK 9+ when deployed as a WAR on Tomcat; Spring Boot executable jars are not affected. Multiple vendors reported limited in-the-wild exploitation; Spring released patches on April 1, 2022 (upgrade to Spring Framework 5.3.18 or 5.2.20+) and provided workarounds for those unable to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.