logo

SpringShell Remote Code Execution Vulnerability

ID: 628d3465-e207-57fa-b76c-45805352132c

STIX ID: report--628d3465-e207-57fa-b76c-45805352132c

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This report analyzes the SpringShell (CVE-2022-22965) remote code execution vulnerability in Spring Framework, explains how maliciously crafted requests can leverage data binding on Tomcat WAR deployments to write JSP web shells, documents observed exploitation used to download and run Mirai botnet binaries, and provides IOCs, YARA rules, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.