Get real-time updates on Telegram
CVE-2026-40994, CVE-2026-40995, CVE-2026-40996 +3 more CVEs: Affected product not specified by the source
CVE-2026-40994, CVE-2026-40995, CVE-2026-40996, CVE-2026-40997, CVE-2026-40999, CVE-2026-41000 affects org.springframework.ws:spring-ws-bom. EPSS 0.00339 (percentile 0.25043), scored 2026-10-05. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2.
CVE-2026-40994
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-40995
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-40996
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-40997
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-40999
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
CVE-2026-41000
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
- CVE
- CVE-2026-40997, CVE-2026-40999, CVE-2026-41000
- Product
- org.springframework.ws:spring-ws-bom
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00339 · percentile 0.25146 · 2026-10-06
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- OSV.dev · Source record · observed 2026-10-07 03:19:31.921362+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-40994.html