VMWARE disclosed four high-severity vulnerabilities affecting Spring frameworks on August 20, 2026. These include issues in Spring Data REST and Spring AI, with impacts such as privilege escalation and denial of service. Key vulnerabilities are CVE-2026-47849 related to JSON Patch property mutation, CVE-2026-59279 involving session exhaustion, and others leading to crashes and integrity risks. Affected versions include Spring Data REST up to 5.1.0 and Spring AI 2.0.0. Patching is advised with specific upgrades available for mitigation.
VMware fixes high severity Spring flaws after August 2026 alert
CyberSIXT Evidence Panel
Article by CyberSIXT