Back Heise.De Numerous security vulnerabilities threaten VMware Tanzu Spring software
VMware Tanzu has released numerous security updates for various Spring software products. If attacks are successful, attackers can gain access to Spring Security instances, for example, as an administrator. Currently, there are no reports that attackers are already exploiting the vulnerabilities.
Because a complete list of security vulnerabilities would exceed the scope of this report, admins must study the security section of the Spring website . There they will find specific information the affected software and which versions have been fixed.
The majority of the vulnerabilities are classified with the threat level “ medium. ” One vulnerability (CVE-2026-59270) is classified as “ critical. ” Here, attackers can access instances as administrators due to errors in the context of the LDAP server. This allows them to access registration data, among other things, or even manipulate the identities of other users. Such a position is often also a starting point for further attacks (lateral movement).
Unauthorized access to Spring Security is conceivable due to WebAuthn errors (CVE-2026-47841 “ high ”).
Spring AI is vulnerable to a malware attack (CVE-2026-47851 “ high ”). Here, attackers must trick victims into accepting a prepared PDF. If it is opened, errors occur during processing, and attackers can access memory areas that are not actually intended. This usually leads to crashes or malware on systems.
Through the successful exploitation of a vulnerability (CVE-2026-59288 “ high ”) in Spring GraphQL, attackers can gain unauthorized access to actually isolated data by sending a manipulated URL.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
