Vulnerabilities

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer

The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal.

VMware

Broadcom announced on Tuesday that new VMware Avi Load Balancer updates patch several critical and high-severity vulnerabilities.

VMware Avi Load Balancer is a software-defined platform that provides load balancing, application security, and analytics for applications in hybrid and multi-cloud environments.

According to Broadcom, two external researchers recently discovered that the VMware product is affected by seven potentially serious vulnerabilities.  

Filip Waeytens of NATO’s technology and cyber hub has been credited with discovering CVE-2026-47865, a critical authentication bypass issue that allows an attacker with network access to breach the Avi control plane.

Waeytens also discovered three high-severity vulnerabilities that can allow an attacker to bypass authentication, execute arbitrary code, and escalate privileges to root. Network or local access is required for the exploitation of these flaws, which are tracked as CVE-2026-47866, CVE-2026-47867 and CVE-2026-47868.

Lang Khuong Duy of Viettel IDC discovered two high-severity Avi Load Balancer bugs that can be exploited for directory traversal attacks (CVE-2026-47871) and privilege escalation (CVE-2026-47870).

Advertisement. Scroll to continue reading.

Both Lang and Waeytens have been credited by Broadcom for responsibly reporting CVE-2026-47869, a high-severity remote code execution vulnerability that can be exploited by an authenticated attacker with network access.

Broadcom’s advisory does not mention in-the-wild exploitation for any of these vulnerabilities. 

However, it’s important that organizations install the latest updates, as it’s not uncommon for threat actors to exploit VMware product flaws in their attacks.

Related: High-Severity Vulnerability Patched in VMware Fusion

Related: VMware Aria Operations Vulnerability Could Allow Remote Code Execution

Related: 2024 VMware Flaw Now in Attackers’ Crosshairs

Related Content

Artificial Intelligence

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Vulnerabilities

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

Vulnerabilities

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

Endpoint Security

Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.

Vulnerabilities

Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.

Vulnerabilities

Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.

Vulnerabilities

PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version