CVE-2026-59272: VMware Spring Advanced Message Queuing Protocol

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

Affected products

  • VMware Spring Advanced Message Queuing Protocol: before 2.4.19 (fixed in 2.4.19); from 3.2.0, before 3.2.13 (fixed in 3.2.13); from 4.0.0, before 4.0.4.1 (fixed in 4.0.4.1); from 4.1.0, before 4.1.0.1 (fixed in 4.1.0.1)

Published 2026-08-27. Last modified 2026-09-01.