Site icon VMVirtualMachine.com

Numerous security vulnerabilities threaten VMware Tanzu Spring software

Numerous security vulnerabilities threaten VMware Tanzu Spring software

VMware Tanzu has released numerous security updates for various Spring software products. If attacks are successful, attackers can gain access to Spring Security instances, for example, as an administrator. Currently, there are no reports that attackers are already exploiting the vulnerabilities.

Because a complete list of security vulnerabilities would exceed the scope of this report, admins must study the security section of the Spring website. There they will find specific information about the affected software and which versions have been fixed.

The majority of the vulnerabilities are classified with the threat level “medium.” One vulnerability (CVE-2026-59270) is classified as “critical.” Here, attackers can access instances as administrators due to errors in the context of the LDAP server. This allows them to access registration data, among other things, or even manipulate the identities of other…

Exit mobile version