Sonatype tracked 91 Spring CVEs affecting an estimated 209,569 software components in the August 20, 2026 disclosure.
Spring Security’s critical UnboundID LDAP flaw could let remote attackers gain admin access to exposed in-memory LDAP directories.