CVE Tools

91 Vulnerabilities Patched in Spring Application Framework

SecurityWeekBy Eduard Kovacs

PatchSpring FrameworkSpring Security

Our summary

Broadcom has released updates for the Spring application framework addressing 91 vulnerabilities across various modules, including Spring Security, Spring AI, and Spring GraphQL. Among these fixes is a critical flaw in Spring Security’s embedded LDAP server (CVE-2026-59270) that permits unauthorized modification of directory entries, alongside over a dozen high-severity issues enabling remote code execution and data leakage. The scale of this update impacts more than 200,000 downstream components, highlighting how the increased use of AI-assisted coding by Broadcom has accelerated the emergence of security defects in the ecosystem.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store