VMWARE disclosed seven critical vulnerabilities in Spring GraphQL and related Spring Cloud products on August 20, 2026, all categorized as HIGH severity. The most concerning vulnerability, CVE-2026-59285, allows unsafe deserialization, which can lead to remote code execution. Other vulnerabilities include potential denial of service, data leaks, and file access risks. Affected versions include multiple branches of Spring for GraphQL and Spring Cloud components. Patches are available in newer versions, and mitigations can be applied if immediate upgrades are not feasible.
CVE-2026-59285 lets attackers run code via VMware Spring GraphQL
CyberSIXT Evidence Panel
Article by CyberSIXT