Critical Alert 1 Active Exploit Detected Today

CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability →
Powered by CVE Watchtower
×
August 9, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-22737NVD

Vulnerability Summary

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Severity Level
MEDIUM(5.9)
Published Date
Mar 20, 2026
Last Modified
Apr 23, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.09%Probability
Root Weakness (CWE)
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone