A critical alert has been issued regarding two high-severity vulnerabilities in Spring Integration: CVE-2026-59307 and CVE-2026-59324. CVE-2026-59307 allows remote code execution through a deserialization flaw, while CVE-2026-59324 exposes sensitive information due to cross-message header leakage. These vulnerabilities pose serious risks to enterprise systems, enabling attackers to execute arbitrary code or access sensitive data. Administrators are urged to upgrade to fixed versions immediately.
Current affected software versions are unspecified, and no active exploitation has been confirmed. Suggested mitigation includes modifying function signatures for the header leakage vulnerability.