Skip to content
Vulnerability intelligence

CVE-2026-40987 — Spring Vulnerability

In 15 days, enterprises running Spring 6.2 lose open-source security patches on the same day the EU requires them to prove they have a patching strategy. Spring 7.0 is the upgrade path. The migration window is two weeks.

CVSS 7.1 Spring 2026