Spring disclosed and national cyber agencies amplified six vulnerabilities in Spring Tools that affect developer environments for the Spring Java ecosystem, including Spring Tools for Eclipse 5.2.0 and earlier and Spring Tools for VSCode, Cursor, and Theia 2.2.0 and earlier. The most serious issues include CVE-2026-47858, which can expose Spring Boot applications started with live information mode to JMX-based remote code execution, and CVE-2026-47873, where the Boot Dashboard Docker integration publishes unauthenticated JDWP and JMX ports on 0.0.0.0 instead of limiting access to loopback, potentially exposing container control interfaces to the network.
A third high-severity flaw, CVE-2026-47882, weakens Spring Boot DevTools remote restart authentication by generating the shared secret with a non-cryptographic pseudo-random number generator. Advisories also cited additional issues involving plaintext logging of proxy credentials, cleartext storage of remote secrets, and a cross-site scripting vulnerability. Italy's ACN and the Canadian Centre for Cyber Security said updates are available or pending through Spring security bulletins, with fixed versions identified as Spring Tools for Eclipse 5.3.0 and Spring Tools for VSCode, Cursor, and Theia 2.3.0, and urged organizations to upgrade affected tooling.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-759 warning that multiple Spring developer tooling products were affected by several vulnerabilities as of July 30, 2026. The advisory directed users and administrators to review Spring security advisories and apply updates when available.
Spring published security advisories covering six newly disclosed vulnerabilities in Spring Tools products, including remote code execution, exposed JDWP and JMX ports, weak secret generation, plaintext credential logging, cleartext secret storage, and cross-site scripting. The affected versions include Spring Tools for Eclipse 5.2.0 and earlier and Spring Tools for VSCode, Cursor, and Theia 2.2.0 and earlier.
VMware security received new CVE records for multiple vulnerabilities affecting Spring developer tooling, including CVE-2026-47882 and CVE-2026-47858. The issues include weak secret generation and JMX-based remote code execution conditions in Spring Tools products.
Security updates were made available to address the six disclosed Spring Tools vulnerabilities. The notice says affected products are Spring Tools for Eclipse before 5.3.0 and Spring Tools for VSCode, Cursor, and Theia before 2.3.0, and recommends updating to fixed versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourceacn.gov.it
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.