91 Spring CVEs: The AI Vulnerability Consumption Problem
Brief
TL;DR
- Broadcom released a large batch of Spring security advisories on August 20, 2026, with Sonatype tracking 91 CVEs across Spring Framework and related projects.
- At the time of publishing, Sonatype Guide currently identifies 209,569 software components affected by the security event.
- The disclosure comes amid a dramatic rise in AI-assisted vulnerability discovery . Broadcom previously reported a more than 1,700% increase in monthly Spring security advisories from March to April 2026.
- AI is making vulnerability discovery faster, but organizations still have to determine where vulnerable components are deployed, prioritize risk, and identify safe remediation paths.
On August 20, 2026, Broadcom published a large collection of security advisories affecting Spring and related projects.
The vulnerabilities span multiple Spring projects and include several high-severity issues.
