Skip to content
Numerous security vulnerabilities threaten VMware Tanzu Spring software

Numerous security vulnerabilities threaten VMware Tanzu Spring software

Heise.De • August 24, 2026

VMware Tanzu has released numerous security updates for various Spring software products. If attacks are successful, attackers can gain access to Spring Security instances, for example, as an administrator. Currently, there are no reports that attackers are already exploiting the vulnerabilities.

Because a complete list of security vulnerabilities would exceed the scope of this report, admins must study the security section of the Spring website . There they will find specific information the affected software and which versions have been fixed.

The majority of the vulnerabilities are classified with the threat level “ medium. ” One vulnerability (CVE-2026-59270) is classified as “ critical. ” Here, attackers can access instances as administrators due to errors in the context of the LDAP server. This allows them to access registration data, among other things, or even manipulate the identities of other users. Such a position is often also a starting point for further attacks (lateral movement).

Unauthorized access to Spring Security is conceivable due to WebAuthn errors (CVE-2026-47841 “ high ”).

Spring AI is vulnerable to a malware attack (CVE-2026-47851 “ high ”). Here, attackers must trick victims into accepting a prepared PDF. If it is opened, errors occur during processing, and attackers can access memory areas that are not actually intended. This usually leads to crashes or malware on systems.

Through the successful exploitation of a vulnerability (CVE-2026-59288 “ high ”) in Spring GraphQL, attackers can gain unauthorized access to actually isolated data by sending a manipulated URL.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.