Synced 16 Jun 2026 15:24 UTC Account

Is Spring Security 6.2.8 patched?

VMware · cycle 6.2 · end of life · Official site ↗
6.2.840/100End of life

Current stable (7.1.0): 100/100

Health score40/100
Open issues1
Exploited now0
Cycle 6.2 EOL2024-12-31
Latest release7.1.0

Summary iPlain-English security status for Spring Security 6.2.8, built from its CVEs, active-exploitation data, end-of-life date and latest release.

Spring Security 6.2.8 is part of the 6.2 release line. 1 known vulnerability affects it. The 6.2 line reached end-of-life on 2024-12-31, so it no longer receives security patches. The latest supported Spring Security release is 7.1.0.

Known issues affecting 6.2.8

Exploited first, then by exploitation probability.

CVE-2026-22748 MEDIUM EPSS 0% → fixed in 7.0.5

Frequently asked

Is Spring Security 6.2.8 patched?

Spring Security 6.2.8 is end-of-life and no longer receives security patches. Move to 7.1.0.

When does Spring Security 6.2 reach end-of-life?

Spring Security 6.2 reached end-of-life on 2024-12-31 and no longer receives security patches.

What is the latest version of Spring Security?

The latest supported Spring Security release is 7.1.0.

Is Spring Security 6.2.8 still receiving security updates?

No — Spring Security 6.2.8 is on the 6.2 line, which reached end-of-life on 2024-12-31 and no longer receives security updates. Upgrade to 7.1.0 or later to stay supported.

Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against VMware's official advisory before you patch or upgrade — Spring Security official site ↗