VMware (Broadcom) Security Advisories & CVEs
25 advisories tracked · VMware Security Advisories (VMSA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor VMware CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Check if your VMware device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in VMware's recent advisories.
Official source
VMware Security Advisories (VMSA) via NVD
Broadcom's VMSA portal is a JavaScript app with no stable public feed, so VulniPulse ingests VMware CVEs from NVD filtered to VMware's own CNAs (security@vmware.com and Broadcom's successor CNA) — official, CNA-published data covering ESXi, vCenter Server, NSX, Aria/vRealize, Cloud Foundation, Workstation/Fusion and VMware Tools. Each entry links back to the Broadcom/VMware advisory when NVD carries the reference.
Latest VMware advisories
Low [CVE-2026-59314] Spring Framework: Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response sp…
Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. Spring Framework 7.0.0 - 7.0.8
Low [CVE-2026-59306] Spring Cloud: Potential for deserialization of untrusted types in Spring Cloud Stream.
Potential for deserialization of untrusted types in Spring Cloud Stream.
Low [CVE-2026-59305] Spring Cloud: Partition interceptor may be improperly added while sending message.
Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2
Low [CVE-2026-59304] Spring Cloud: Improper caching of the original content type in Spring Cloud Stream Avro.
Improper caching of the original content type in Spring Cloud Stream Avro.
Low [CVE-2026-59303] Spring Cloud: Dynamic destination cache size is not properly bound in Spring Cloud Stream.
Dynamic destination cache size is not properly bound in Spring Cloud Stream.
Low [CVE-2026-59302] Spring Cloud: Potential for logging sensitive data in Spring Cloud Stream.
Potential for logging sensitive data in Spring Cloud Stream.
Low [CVE-2026-59301] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function Azure.
Potential for logging sensitive data in Spring Cloud Function Azure.
Low [CVE-2026-59300] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function AWS.
Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 3.2.16 and earlier
Low [CVE-2026-59299] Spring Cloud: Composition lookup can potentially poison base function in Spring Cloud Function.
Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier
Low [CVE-2026-59298] Spring Cloud: Potential for improper filtering of HTTP headers in Spring Cloud Function.
Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier
Low [CVE-2026-59297] Spring Cloud: Implementation of isSecure call of ServerlessHttpServletRequest does not verify the actual scheme.
Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3
Low [CVE-2026-59291] Spring Cloud: Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.
Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.
Low [CVE-2026-59277] Spring Security: Spring Security's InetAddressMatchers utility provides matchInternal and matchExternal builders for constructing…
Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network.
Low [CVE-2026-41709] ESX insufficient logging vulnerability
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.
Low [CVE-2026-59326] Spring Boot: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment v…
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Low [CVE-2026-59269] user authenticating to Kubernetes clusters via the Pinniped Supervisor
A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were true: the Pinniped Supervisor server is running with an ActiveDirectoryIdentityProvider resource configured; the ActiveDirectoryIdentityProvider.spec.groupSearch.attributes.groupName is empty; the attacker gains the ability to edit some part of the distinguished name (DN) of group entries in the Active Directory (AD) server's database for groups to which they belong; the configured group search parameters cause the edited group to be included in the group search results for the user; and the attacker knows the password for an AD user who belongs to the edited AD group. Affected versions: Pinniped (go.pinniped.dev) v0.11.0 through v0.46.0 inclusive; fixed in v0.47.0.
Low [CVE-2026-41000] Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
Low [CVE-2026-41694] Spring Security: Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses wit…
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
Low [CVE-2026-41852] Spring Framework: vulnerability in Spring Expression Language (SpEL) evaluation logic
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected product named by the advisory: Spring Framework.
Low [CVE-2026-41848] Spring Framework: Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a…
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected product named by the advisory: Spring Framework.