Broadcom released Spring framework updates that fix 91 security vulnerabilities affecting widely used Java application components. The issues include CVE-2026-59270 in Spring Security’s embedded UnboundID LDAP server, which could let an attacker authenticate and modify in-memory directory entries, plus CVE-2026-59285, described by Sonatype as a critical remote-code-execution flaw in Spring for GraphQL, and CVE-2026-59318 in Spring AI that can enable privilege escalation through prompt injection. The fixes affect projects including Spring Security, Spring AI, Cloud Config, Data REST, Integration, Reactor Core, Reactor Netty, AMQP, and Batch.
Why it matters: Spring is deeply embedded in enterprise software, so these flaws can ripple into many internal and customer-facing applications. Organizations using Spring-based software should urgently inventory affected components and apply the latest updates, especially where internet-facing services use Spring Security or Spring for GraphQL.
Eduard Kovacs
2026.08.24
100% relevant
This article establishes a new tracked story because it centers on a newly announced broad Spring patch wave with 91 vulnerabilities and specific CVEs, rather than updating an existing SecLog story about the same event.
← Back to all stories