Broadcom Security Advisories · April 2026 — Broadcom Security Advisories
52 advisories 52 CVEs

VMware, Bitnami, Cloud Foundry, and Tanzu advisories for 2026-04. Mirrored into Vulnetix VDB with downloadable CSAF where available.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2026-40976

Cloud Foundry / TanzuActive exploitation (sightings)CRITICAL2026-04-23

Spring Boot's default security filter chain has no authorization rule with Actuator but without Health

CVEs:CVE-2026-40976

Upstream advisory

CVE-2026-22745

Cloud Foundry / TanzuActive exploitation (sightings)2026-04-19

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources

CVEs:CVE-2026-22745

Upstream advisory

CVE-2026-40971

Cloud Foundry / TanzuActive exploitation (sightings)2026-04-23

Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker

CVEs:CVE-2026-40971

Upstream advisory

CVE-2026-40970

Cloud Foundry / TanzuActive exploitation (sightings)2026-04-23

Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.

CVEs:CVE-2026-40970

Upstream advisory

CVE-2026-22751

Cloud Foundry / TanzuCoalition ESS < 30%2026-04-21

Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured

CVEs:CVE-2026-22751

Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.