BROADCOM'S Spring application development framework has released updates addressing 91 vulnerabilities, including a critical one (CVE-2026-59270) that allows potential unauthorized access through its embedded LDAP server. The vulnerabilities, which number over 200 this year, vary in severity, affecting various Spring components including Spring Security and Spring AI. Notable vulnerabilities include CVE-2026-59285 (critical remote code execution) and CVE-2026-59318 (medium-severity privilege escalation).
Cybersecurity firm Sonatype indicates these vulnerabilities could impact over 200,000 software components. Open source projects are urged to apply the latest patches.