Spring Cloud Config Server companion CVE (MEDIUM)
cve · CVE-2026-41004
Coverage timeline
2
first 2026-05-09 → last 2026-05-10
Briefs
2
2 distinct
Sources cited
23
18 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
Story timeline
Source distribution
- attack.mitre.org2 (9%)
- onapsis.com2 (9%)
- security-hub.ncsc.admin.ch2 (9%)
- securityweek.com2 (9%)
- thehackernews.com2 (9%)
- bleepingcomputer.com1 (4%)
- blog.calif.io1 (4%)
- ccb.belgium.be1 (4%)
- other10 (43%)
External references
All cited sources (23)
- spring.ioprimaryinlineSpring.iohttps://spring.io/security/cve-2026-40982
- attack.mitre.orginlineT1083 (File and Directory Discovery)https://attack.mitre.org/techniques/T1083/
- attack.mitre.orginlineT1530 (Data from Cloud Storage)https://attack.mitre.org/techniques/T1530/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-11https://www.bleepingcomputer.com/news/security/github-announces-npm-security-changes-to-tackle-supply-chain-attacks/
- blog.calif.ioinlineCalif.io, 2026-06-18https://blog.calif.io/p/squidbleed-cve-2026-47729
- ccb.belgium.beinlineCCB, 2026-06-09https://ccb.belgium.be/advisories/warning-sap-addresses-critical-vulnerabilities-affecting-multiple-sap-products-patch
- cert.ssi.gouv.frinlineCERT-FR CERTFR-2026-AVI-0543, 2026-05-07https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0543/
- github.bloginlineGitHub Changelog, 2026-06-09https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
- github.cominlineGitHub Security Advisory GHSA-c9ph-gxww-7744, 2026-04-29https://github.com/thymeleaf/thymeleaf/security/advisories/GHSA-c9ph-gxww-7744
- herodevs.cominlineHeroDevs analysis, 2026-05-08https://www.herodevs.com/blog-posts/cve-2026-40982-critical-spring-cloud-config-server-directory-traversal-cvss-9-8
- onapsis.cominlineOnapsis, 2026-06-09https://onapsis.com/blog/sap-security-patch-day-june-2026
- onapsis.cominlineOnapsis, 2026-05-12https://onapsis.com/blog/sap-security-patch-day-may-2026/
- scworld.cominlineSC World, 2026-05-22https://www.scworld.com/brief/belarus-linked-ghostwriter-group-targets-ukraine-using-prometheus-learning-platform-lures
- securelist.cominlineSecurelist (Kaspersky), 2026-05-12https://securelist.com/state-of-ransomware-in-2026/119761/
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub #12565, 2026-05-12https://security-hub.ncsc.admin.ch/#/posts/12565
- security-hub.ncsc.admin.chinlineNCSC-CH, 2026-06-09https://security-hub.ncsc.admin.ch/#/posts/12620
- securityweek.cominlineSecurityWeek, 2026-06-22https://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/
- securityweek.cominlineSecurityWeek, 2026-05-12https://www.securityweek.com/sap-patches-critical-s-4hana-commerce-vulnerabilities/
- support.sap.cominlineSAP, 2026-06-09https://support.sap.com/en/my-support/knowledge-base/security-notes-news/june-2026.html
- techzine.euinlineTechzine, 2026-02-16https://www.techzine.eu/news/security/138806/data-breach-at-odido-responsibility-and-compensation-under-discussion/
- thehackernews.cominlineThe Hacker News, 2026-05-22https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html
- thehackernews.cominlineThe Hacker News, 2026-06-22https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html
- theregister.cominlineThe Register, 2026-02-27https://www.theregister.com/2026/02/27/odido_shinyhunters_leaks/
Items in briefs about Spring Cloud Config Server companion CVE (MEDIUM)
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.