securityonline.info 8/21/2026, 5:11:16 PM · external

VMware fixes high severity Spring flaws after August 2026 alert

VMware fixes high severity Spring flaws after August 2026 alert
CyberSIXT Evidence Panel
Primary Source spring.io
CISA KEV Not in KEV
Patch Patch Status Unknown

VMWARE disclosed four high-severity vulnerabilities affecting Spring frameworks on August 20, 2026. These include issues in Spring Data REST and Spring AI, with impacts such as privilege escalation and denial of service. Key vulnerabilities are CVE-2026-47849 related to JSON Patch property mutation, CVE-2026-59279 involving session exhaustion, and others leading to crashes and integrity risks. Affected versions include Spring Data REST up to 5.1.0 and Spring AI 2.0.0. Patching is advised with specific upgrades available for mitigation.

View Primary Source Via securityonline.info

Article by CyberSIXT