View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Broadcom discloses 91 Spring CVEs affecting 209,569 tracked components

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Trojanized npm Packages Deliver RedC2 4.0 Linux Backdoor
    Trojanized npm packages are delivering the RedC2 4.0 Linux backdoor.

    • npm users of calendar and streak utility packages are affected.
    • The packages contain the RedC2 4.0 Linux implant.
    • When loaded, the module locates its bundled binary and marks it executable.
    • The binary launches as a detached background process.
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • Broadcom discloses 91 Spring CVEs affecting 209,569 tracked components
    Broadcom disclosed 91 CVEs across Spring projects.

    • Spring Framework users and applications using Spring Security, Spring Cloud Config, Spring AI, Spring Data REST, Spring Integration, Reactor, Spring AMQP, or Spring Batch are affected.
    • The disclosure covers insecure deserialization, code execution, sensitive-information exposure, SSRF, path traversal, denial of service, and authorization flaws.
    • CVE-2026-59285 is a critical Spring for GraphQL deserialization flaw rated CVSS 9.2.
    • Exploitation may occur when applications use Jackson 2.x, expose paginated GraphQL fields, and contain abuse-prone classes; AI-assisted scanning is accelerating vulnerability discovery.
      ๐Ÿ“„ Source: spring.io ยท ๐Ÿ“Ž Coverage: sonatype.com ยท ๐Ÿ‘ via securityboulevard.com (discovered)

๐Ÿ”“ CVEs & KEV

  • CVE-2026-77810 โ€” CVSS 9.4 โ€” Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connect...

  • CVE-2026-67359 โ€” CVSS 8.7 โ€” Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3....

  • CVE-2026-74252 โ€” CVSS 8.6 โ€” Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1...

  • CVE-2026-54682 โ€” CVSS 8.2 โ€” DiscordChatExporter: Stored XSS in HTML export when markdown formatting is di...

  • CVE-2026-54071 โ€” CVSS 7.8 โ€” BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldo...

  • CVE-2026-27462 โ€” CVSS 7.5 โ€” Combodo iTop: User enumeration via password resetCombodo iTop is a web based ...

  • CVE-2026-30866 โ€” CVSS 7.5 โ€” Combodo iTop: Insecured access to uploaded images via sniffed urlCombodo iTop...

  • CVE-2026-67361 โ€” CVSS 6.9 โ€” Joomla Extension - j2commerce.com - Unauthenticated file upload with missing ...

  • CVE-2026-67360 โ€” CVSS 6.3 โ€” Joomla Extension - j2commerce.com - Cross-customer order replication in J2Sto...

  • CVE-2026-53762 โ€” CVSS 6.2 โ€” VeraCryp: wolfCrypt backend bypasses VeraCrypt PBKDF2 iteration count (non-de...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check