Spring had 16 CVEs in all of 2025 — it has passed 200 this year, and the reason is that AI is now looking
2026-08-25Security
Broadcom shipped 91 vulnerability fixes for the Spring framework in one release, including a critical flaw in Spring Security's embedded LDAP server. The count went 22, then 16, then over 200. The jump is attributed to Broadcom putting AI on the problem, which is the same capability the attack stories run on, pointed the other way.