[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMpEi2dUtmcNeAsbBZxAIQ59M3uPj3ck4GgM3ln8KYlU":3},{"article":4,"iocs":57},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"80e0ea44-c621-4cd5-807f-5173d67e93a9","91 Vulnerabilities Patched in Spring Application Framework","91-vulnerabilities-patched-in-spring-application-framework-6dfa71","More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek.","Broadcom's Spring application development framework has released updates addressing 91 vulnerabilities, with one critical flaw (CVE-2026-59270) affecting its embedded LDAP server. Over a dozen high-severity vulnerabilities are also included, enabling attacks like XSS, RCE, and DoS. The surge in vulnerabilities is attributed to Broadcom's increased use of AI in development, with over 200 vulnerabilities patched this year alone, a significant increase from previous years.","Spring application framework releases updates patching 91 vulnerabilities, including one critical.","The developers of Broadcom’s Spring application development framework last week announced the release of updates that patch 91 vulnerabilities. Spring is an open source application framework for the Java platform that simplifies the creation of enterprise applications through features such as dependency injection, aspect-oriented programming, and modular support for web, data, and messaging architectures. After years under VMware’s stewardship, it transitioned to Broadcom following its acquisition of VMware. A single vulnerability has been assigned a critical severity rating: CVE-2026-59270. It affects Spring Security’s embedded UnboundID LDAP server and could allow an attacker to authenticate and modify entries in the in-memory directory. Over a dozen vulnerabilities have been classified as high severity. They can be exploited for XSS attacks, information disclosure, remote code execution, DoS attacks, security bypasses, and unauthorized access. The remaining vulnerabilities have medium and low severity ratings. Cybersecurity firm Sonatype has analyzed the patches and found that they impact more than 200,000 software components. The security flaws affect projects such as Spring Security, Spring AI, Cloud Config, Data REST, Integration, Reactor Core, Reactor Netty, AMQP, and Batch.Advertisement. Scroll to continue reading. Sonatype has highlighted two vulnerabilities: CVE-2026-59285, which it describes as a critical remote code execution issue in Spring for GraphQL, and CVE-2026-59318, a medium-severity issue in Spring AI’s tool-calling functionality that can allow privilege escalation through prompt injection. The surge in Spring vulnerabilities is unsurprisingly driven by Broadcom’s use of AI. More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. Spring vulnerabilities can be useful to threat actors, and they have been exploited in the wild, including the notorious Spring4Shell. CISA’s KEV catalog currently includes several such vulnerabilities. Open source projects are advised to review the latest Spring patches and apply them. Related: Critical Isolated-vm Vulnerability Leads to RCE on Host Related: CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Related: Hackers Target Zimbra Servers in Active Exploitation Campaign Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Contractors’ CMMC Confidence Rises as Ability to Prove It Falls BehindHackers Target Zimbra Servers in Active Exploitation CampaignOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesHackers Using AI to Target Siemens PLCs in Critical US SectorsCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignCareCloud Data Breach Impact Grows to 3.7 Million IndividualsFortinet Acquires AI Security Company Virtue AIIrregular Details How a Naming Error Let AI Models Attack a Real Company Latest News Venezuelan Gets Record Federal Prison Term for ATM JackpottingPersonal Information Exposed in Apollo Global Data BreachRethinking Application Security for the AI EraIran-Linked Hackers Shut Down UK Power Plant for Four DaysTikTok Reaches $400 Million Settlement With US Justice Department Over Children’s PrivacyAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightFormer NSA Director Paul Nakasone Launches National Security Advisory Firm Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveVensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.WISeKey has appointed Alexander Hirsch as Group Chief Marketing Officer.UltraViolet Cyber has named Andrew Park Chief Information Security Officer.More People On The MoveExpert Insights Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002F91-vulnerabilities-patched-in-spring-application-framework\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F12\u002FCode-3rd-Party-Risk.jpg","2026-08-24T11:58:28+00:00","2026-08-24T12:00:09.5658+00:00",8,[18,21,24,26,28,31],{"name":19,"type":20},"Broadcom","vendor",{"name":22,"type":23},"Spring Application Framework","product",{"name":25,"type":23},"Spring Security",{"name":27,"type":23},"Spring AI",{"name":29,"type":30},"LDAP","technology",{"name":32,"type":33},"Spring4Shell","campaign","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":34,"icon":36,"name":37,"slug":38},null,"Vulnerabilities","vulnerabilities",[40,42,47,52],{"category":41},{"id":34,"icon":36,"name":37,"slug":38},{"category":43},{"id":44,"icon":36,"name":45,"slug":46},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":48},{"id":49,"icon":36,"name":50,"slug":51},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":53},{"id":54,"icon":36,"name":55,"slug":56},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[58,62,65],{"type":59,"value":60,"context":61},"cve","CVE-2026-59270","Critical severity vulnerability in Spring Security's embedded UnboundID LDAP server.",{"type":59,"value":63,"context":64},"CVE-2026-59285","Critical remote code execution issue in Spring for GraphQL.",{"type":59,"value":66,"context":67},"CVE-2026-59318","Medium-severity issue in Spring AI's tool-calling functionality allowing privilege escalation."]