cbcvebase.
CVE-2026-47861
published 2026-08-27

CVE-2026-47861: An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP…

PriorityP347medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.25%
16.6th percentile
An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

Affected

10 ranges
VendorProductVersion rangeFixed in
springspring_integration<= 5.5.21
springspring_integration
springspring_integration6.4.0 – 6.4.12
springspring_integration6.5.0 – 6.5.10
springspring_integration7.0.0 – 7.0.5
vmwarespring_integration< 5.5.225.5.22
vmwarespring_integration>= 6.4.0 < 6.4.136.4.13
vmwarespring_integration>= 6.5.0 < 6.5.116.5.11
vmwarespring_integration>= 7.0.0 < 7.0.5.17.0.5.1
vmwarespring_integration>= 7.1.0 < 7.1.0.17.1.0.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.