CVE-2022-22965
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
11 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.46%
probability
This CVE has a 94.46% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
BobTheShoplifter/Spring4Shell-POC
Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965
376
reznok/Spring4Shell-POC
Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit
325
TheGejr/SpringShell
Spring4Shell - Spring Core RCE - CVE-2022-22965
131
SecNN/SpringFramework_CVE-2022-22965_RCE
SpringFramework 远程代码执行漏洞CVE-2022-22965
73
4nth0ny1130/spring4shell_behinder
CVE-2022-22965写入冰蝎webshell脚本
63
Mr-xn/spring-core-rce
CVE-2022-22965 : about spring core rce
50
FourCoreLabs/spring4shell-exploit-poc
Exploit a vulnerable Spring application with the Spring4Shell (CVE-2022-22965) Vulnerability.
44
7 repos — triés par ⭐
Rechercher sur GitHub ↗
Spring patches leaked Spring4Shell zero-day RCE vulnerability
BleepingComputer
Mar 31, 2022
Defense Lessons From the Black Basta Ransomware Playbook
Qualys
Feb 25, 2025
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
Qualys
May 08, 2025
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
Qualys
Aug 23, 2022
Security Advisory 2022-023
CERT-EU
Mar 31, 2022
Spring Framework Zero-Day Remote Code Execution (Spring4Shell) Vulnerability
Qualys
Mar 31, 2022
Oracle Patch Tuesday April 2023 Security Update Review
Qualys
Apr 19, 2023
The January 2023 Oracle Critical Patch Update
Qualys
Jan 18, 2023
Signal Intelligence
Confidence
85%
EPSS
94.46%
Mentions
11
Last Seen
May 08, 2025
CNA Information
Analyst Note
CVE-2022-22965 (Spring4Shell) was exploited in the wild immediately after public disclosure on 2022-04-01, with exploitation documented before patches were widely available. The CRITICAL CVSS score, rapid real-world attacks, and CERT-EU security advisory confirm active exploitation coinciding with vulnerability disclosure, meeting zero-day criteria despite not being in Google Project Zero or CISA KEV.
Threat Actors 12
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Cobalt
apt_group
Financial crime
🇷🇺 RU
Cron
apt_group
🇷🇺 RU
Harvester
apt_group
Information theft and espionage
Unknown
Kinsing
apt_group
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
TeamTNT
apt_group
🇩🇪 DE
Rocke
apt_group
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Operation Shadow Force
apt_group
🇨🇳 CN
Operation Black Atlas
apt_group
Financial crime
Triage Info
Decided atMar 05, 2026