Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    91 Vulnerabilities Patched in Spring Application Framework

    August 25, 2026

    Unitree Claims New Humanoid Robot Outruns Usain Bolt

    August 25, 2026

    The Sonos Roam 2 is back down to its lowest price in months

    August 25, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»91 Vulnerabilities Patched in Spring Application Framework
    91 Vulnerabilities Patched in Spring Application Framework
    Cybersecurity

    91 Vulnerabilities Patched in Spring Application Framework

    The Tech GuyBy The Tech GuyAugust 25, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    The developers of Broadcom’s Spring application development framework last week announced the release of updates that patch 91 vulnerabilities. 

    Advertisement

    Spring is an open source application framework for the Java platform that simplifies the creation of enterprise applications through features such as dependency injection, aspect-oriented programming, and modular support for web, data, and messaging architectures. After years under VMware’s stewardship, it transitioned to Broadcom following its acquisition of VMware.

    A single vulnerability has been assigned a critical severity rating: CVE-2026-59270. It affects Spring Security’s embedded UnboundID LDAP server and could allow an attacker to authenticate and modify entries in the in-memory directory. 

    Over a dozen vulnerabilities have been classified as high severity. They can be exploited for XSS attacks, information disclosure, remote code execution, DoS attacks, security bypasses, and unauthorized access.

    The remaining vulnerabilities have medium and low severity ratings.

    Cybersecurity firm Sonatype has analyzed the patches and found that they impact more than 200,000 software components. The security flaws affect projects such as Spring Security, Spring AI, Cloud Config, Data REST, Integration, Reactor Core, Reactor Netty, AMQP, and Batch.

    Advertisement. Scroll to continue reading.

    Sonatype has highlighted two vulnerabilities: CVE-2026-59285, which it describes as a critical remote code execution issue in Spring for GraphQL, and CVE-2026-59318, a medium-severity issue in Spring AI’s tool-calling functionality that can allow privilege escalation through prompt injection. 

    The surge in Spring vulnerabilities is unsurprisingly driven by Broadcom’s use of AI.

    More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. 

    Spring vulnerabilities can be useful to threat actors, and they have been exploited in the wild, including the notorious Spring4Shell. CISA’s KEV catalog currently includes several such vulnerabilities. 

    Open source projects are advised to review the latest Spring patches and apply them.

    Related: Critical Isolated-vm Vulnerability Leads to RCE on Host

    Related: CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    Related: Hackers Target Zimbra Servers in Active Exploitation Campaign

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Hired for One Job, Judged on Another: The CISO’s Real Problem

    August 25, 2026

    ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

    August 24, 2026

    Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

    August 24, 2026

    Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund

    August 24, 2026

    CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    August 23, 2026

    Microsoft Patches Exploited Entra ID Vulnerability

    August 23, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    91 Vulnerabilities Patched in Spring Application Framework

    August 25, 2026

    Unitree Claims New Humanoid Robot Outruns Usain Bolt

    August 25, 2026

    The Sonos Roam 2 is back down to its lowest price in months

    August 25, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.