← العودة للجدول
CVE-2026-40987
CVE-2026-40987 — A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywher
📅 2026-06-11
🟠 High 🔥 No NVD Exploit Windows CVSS 7.1

📋 الوصف الكامل

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6.3.14; 5.5.0 through 5.5.20.

💻 الأنظمة المتأثرة

Spring Framework

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-40987

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v7.0.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←