logo

Spring Framework RCE Vulnerability CVE-2022-22965 Exploited in the Wild

ID: 8bf5e305-0746-58b5-bfda-4769e5192303

STIX ID: report--8bf5e305-0746-58b5-bfda-4769e5192303

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-22

...
...

A critical zero-day RCE (CVE-2022-22965, "Spring4Shell") impacting Spring MVC and Spring WebFlux on JDK 9+ when deployed as a WAR on Tomcat was disclosed on 2022-03-30 (CVSS 9.8). Vendors reported limited in‑the‑wild exploitation; Spring released fixes (5.3.18 / 5.2.20+) and provided workarounds for users unable to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.