CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-40994, CVE-2026-40995, CVE-2026-40996 +3 more CVEs: Affected product not specified by the source

CVE-2026-40994, CVE-2026-40995, CVE-2026-40996, CVE-2026-40997, CVE-2026-40999, CVE-2026-41000 affects org.springframework.ws:spring-ws-bom. EPSS 0.00339 (percentile 0.25043), scored 2026-10-05. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2. Fixed version: 4.0.15-tuxcare.2.

CVE-2026-40994

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-40995

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-40996

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-40997

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-40999

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-41000

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

Published

CVE
CVE-2026-40997, CVE-2026-40999, CVE-2026-41000
Product
org.springframework.ws:spring-ws-bom
CCR priority
0.1 /100 (P5)
EPSS
0.00339 · percentile 0.25146 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-40994.html