CVE Tools
Back to feed
Patch released Spring Framework rce Spring Security Broadcom web-app

91 Vulnerabilities Patched in Spring Application Framework

SecurityWeek·By Eduard Kovacs··1 min read
CVE Tools coverage

Broadcom has released updates for the Spring application framework addressing 91 vulnerabilities across various modules, including Spring Security, Spring AI, and Spring GraphQL. Among these fixes is a critical flaw in Spring Security’s embedded LDAP server (CVE-2026-59270) that permits unauthorized modification of directory entries, alongside over a dozen high-severity issues enabling remote code execution and data leakage. The scale of this update impacts more than 200,000 downstream components, highlighting how the increased use of AI-assisted coding by Broadcom has accelerated the emergence of security defects in the ecosystem.