CVE-2026-47858: Broadcom Spring Tools

High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier

Affected products

  • Broadcom Spring Tools: before 2.3.0 (fixed in 2.3.0); before 5.3.0 (fixed in 5.3.0)

Published 2026-07-30. Last modified 2026-09-08.