Skip to content

VMware Tanzu Spring Security: Multiple Critical Vulnerabilities Patched

At a glance: Multiple vulnerabilities in VMware Tanzu Spring Security threaten authentication, data protection, and system integrity of affected installations.

The German Federal Office for Information Security (BSI) warns of multiple vulnerabilities in VMware Tanzu Spring Security. These enable information disclosure, authentication bypass, and privilege escalation.

The German Federal Office for Information Security (BSI) has published a security advisory regarding multiple vulnerabilities in VMware Tanzu Spring Security. The flaws enable attackers to disclose sensitive information, circumvent implemented security measures, and impersonate legitimate users.

The technical impacts range from privilege escalation through Server-Side-Request-Forgery (SSRF) to Cross-Site-Scripting attacks (XSS). This puts both the confidentiality and integrity of data processed by the application at risk. For CISOs, these vulnerabilities represent significant software supply-chain risk, particularly when VMware Tanzu Spring Security is deployed in critical or internet-connected systems.

As an immediate measure, affected organisations should verify the current status of their VMware installations and apply outstanding security patches. The BSI advisory via the WID portal provides guidance for prioritising these measures.


Source: wid.cert-bund.de · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: