Broadcom Patches Critical VMware Avi Flaws
A set of seven severe vulnerabilities in the VMware Avi Load Balancer has been addressed following reports from external researchers.
Broadcom has released security updates addressing seven vulnerabilities impacting the VMware Avi Load Balancer, a platform designed for load balancing and application security within hybrid and multi-cloud environments. The patches follow a disclosure process involving two external researchers who identified multiple security weaknesses in the software.
Critical Flaws in Control Plane
The most severe of these vulnerabilities, CVE-2026-47865, is classified as a critical authentication bypass. This flaw permits an attacker who has gained network access to compromise the Avi control plane. The issue was identified by Filip Waeytens, who is affiliated with NATO’s technology and cyber hub.
High-Severity Security Deficiencies
Beyond the critical authentication bypass, researchers identified several other vulnerabilities that carry a high-severity rating. Filip Waeytens is also credited with the discovery of three additional flaws, while Lang Khuong Duy of Viettel IDC identified two further issues. Both researchers collaborated on the report for a seventh vulnerability that requires an authenticated attacker with network access.
- CVE-2026-47866: High-severity vulnerability allowing authentication bypass, arbitrary code execution, and privilege escalation to root.
- CVE-2026-47867: High-severity vulnerability allowing authentication bypass, arbitrary code execution, and privilege escalation to root.
- CVE-2026-47868: High-severity vulnerability allowing authentication bypass, arbitrary code execution, and privilege escalation to root.
- CVE-2026-47871: High-severity directory traversal vulnerability.
- CVE-2026-47870: High-severity privilege escalation vulnerability.
- CVE-2026-47869: High-severity remote code execution vulnerability.
Patching and Risk Mitigation
Broadcom's official advisory does not indicate that any of these specific vulnerabilities have been exploited in the wild at this time. Despite the absence of confirmed malicious activity, the company advises that organizations should prioritize the installation of the latest updates. The potential for these flaws to be leveraged is elevated by the historical tendency for threat actors to exploit VMware product flaws during their operations.
Implications for Infrastructure Security
For IT and security teams, these disclosures underscore the necessity of maintaining a rigorous patching cadence for centralized management platforms like the Avi Load Balancer. Because these vulnerabilities could grant attackers deep access to the control plane or allow for privilege escalation, the exposure window directly impacts the integrity of the broader application environment. Relying on perimeter defenses alone is insufficient when software-defined platforms contain exploitable paths that allow attackers to bypass standard authentication, making prompt deployment of vendor patches a fundamental requirement for securing multi-cloud deployments.
Sources
- SecurityWeek Original source
- advisory Also reporting
- exploit VMware product flaws Also reporting
Continue Reading
GiveWP flaw opens server to unauthenticated takeover
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.
Cosmos EVM Flaw Exploited After Silent Patch Delay
Six blockchains lost funds in August as a critical Cosmos EVM bug went from no-risk assessment to exploited.
Insider Threat Watchdog Sentenced After Spy Leak Plea
DIA insider-threat IT specialist pleads guilty to leaking top-secret intel to an undercover FBI agent.