CVE-2026-59326
Serial number: AV26-759 Date: July 30, 2026 As of July 30, 2026, Spring is affected by vulnerabilities in the following products: Spring Tools for Eclipse Prior to or equal to 5.2.0 Spring Tools for VSCode / Cursor / Theia Prior to or equal to 2.2.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-47858: live information startup mode is vulnerable for remote code execution CVE-2026-47873: Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces CVE-2026-47882: Spring Boot DevTools remote secret generated with a non-cryptographic PRNG CVE-2026-59326: HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server CVE-2026-59327: Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations CVE-2026-59328: Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips Spring | Security Advisories
CSIRTS triage
- What
- Multiple vulnerabilities exist, including one that allows for remote code execution.
- Who is affected
- Users of Spring Tools for Eclipse and Spring Tools for VSCode / Cursor / Theia prior to the specified versions are affected.
- Urgency
- Remediation is necessary, but the vulnerabilities are not actively exploited.
- Action
- Users should review and apply updates as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-59326
Get an email if CVE-2026-59326 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownSpring security advisory (AV26-759)cccs · 2026-07-30
- lowCVE-2026-59326: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/H…nvd · 2026-07-30
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-59326)