Broadcom Security Advisories · March 2026 — Broadcom Security Advisories
28 advisories 28 CVEs 2 EXPLOITED

VMware, Bitnami, Cloud Foundry, and Tanzu advisories for 2026-03. Mirrored into Vulnetix VDB with downloadable CSAF where available.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2026-22738

Cloud Foundry / TanzuActive exploitation (sightings)CRITICAL2026-03-27

Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key

CVEs:CVE-2026-22738

Upstream advisory

CVE-2026-22742

Cloud Foundry / TanzuActive exploitation (sightings)HIGH2026-03-27

Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLs

CVEs:CVE-2026-22742

Upstream advisory

CVE-2026-22744

Cloud Foundry / TanzuActive exploitation (sightings)HIGH2026-03-27

Spring AI Redis Store has TAG Field Query Injection Through Improper Neutralization of Special Characters

CVEs:CVE-2026-22744

Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.