HackMyIP
← Back to News
2026-08-24 SecurityWeek

Broadcom Patches 91 Spring Framework Vulnerabilities, Including Critical RCE Flaws

VulnerabilitySupply ChainAI Security

Broadcom has rolled out a sweeping security update for its Spring application development framework, addressing 91 vulnerabilities in a single release cycle. The patch batch spans nearly every major Spring project, including Spring Security, Spring AI, Cloud Config, Data REST, Integration, Reactor Core, Reactor Netty, AMQP, and Batch. According to software supply chain analysis firm Sonatype, these flaws ripple across more than 200,000 downstream software components, amplifying the potential blast radius for enterprise Java environments.

One vulnerability stands out with a critical severity rating: CVE-2026-59270, which targets the embedded UnboundID LDAP server bundled with Spring Security. If exploited, the flaw could allow an attacker to authenticate against the in-memory directory and modify entries, effectively bypassing access controls. Sonatype separately flagged CVE-2026-59285 as a critical remote code execution issue in Spring for GraphQL. Roughly a dozen additional bugs have been rated high severity, opening paths to cross-site scripting, information disclosure, denial-of-service, security bypasses, and unauthorized access.

Perhaps the most notable addition to this cycle is CVE-2026-59318, a medium-severity flaw in Spring AI's tool-calling functionality that enables privilege escalation through prompt injection. The vulnerability underscores the emerging attack surface of AI-integrated frameworks, where natural language inputs can be weaponized to manipulate autonomous agent behavior. Broadcom's accelerated use of AI in development has correlated with a dramatic rise in reported vulnerabilities: more than 200 Spring CVEs have been published this year alone, compared to just 16 in 2025 and 22 in 2024.

Spring flaws have a documented history of real-world exploitation, including the notorious Spring4Shell bug, and CISA's Known Exploited Vulnerabilities catalog currently lists multiple Spring entries. Organizations running Java-based enterprise applications should prioritize reviewing the patches and updating immediately. Administrators can audit their exposure using a privacy checkup to surface misconfigured services, while developers handling authentication stacks should validate their LDAP integrations with a SSL/TLS checker and verify identity controls through a password checker before deploying the fixes.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →