Sonatype tracked 91 Spring CVEs affecting an estimated 209,569 software components in the August 20, 2026 disclosure.
A critical unsafe deserialization vulnerability in Spring for GraphQL, tracked as CVE-2026-59285, could enable remote code ...
Attackers can target systems with VMware Tanzu Spring AI, Integration, or Security, among others. Security patches are ...
Spring updates patch 91 vulnerabilities, bringing the total count to over 200 in 2026, a surge powered by Broadcom’s use of ...