Breaking
SecurityDeveloping Story

Broadcom Patches Critical VMware Avi Flaws

A set of seven severe vulnerabilities in the VMware Avi Load Balancer has been addressed following reports from external researchers.

··1 month ago·2 min read
a close-up of a server room
Photo by Kier in Sight Archives on Unsplash

Broadcom has released security updates addressing seven vulnerabilities impacting the VMware Avi Load Balancer, a platform designed for load balancing and application security within hybrid and multi-cloud environments. The patches follow a disclosure process involving two external researchers who identified multiple security weaknesses in the software.

Critical Flaws in Control Plane

The most severe of these vulnerabilities, CVE-2026-47865, is classified as a critical authentication bypass. This flaw permits an attacker who has gained network access to compromise the Avi control plane. The issue was identified by Filip Waeytens, who is affiliated with NATO’s technology and cyber hub.

High-Severity Security Deficiencies

Beyond the critical authentication bypass, researchers identified several other vulnerabilities that carry a high-severity rating. Filip Waeytens is also credited with the discovery of three additional flaws, while Lang Khuong Duy of Viettel IDC identified two further issues. Both researchers collaborated on the report for a seventh vulnerability that requires an authenticated attacker with network access.

  • CVE-2026-47866: High-severity vulnerability allowing authentication bypass, arbitrary code execution, and privilege escalation to root.
  • CVE-2026-47867: High-severity vulnerability allowing authentication bypass, arbitrary code execution, and privilege escalation to root.
  • CVE-2026-47868: High-severity vulnerability allowing authentication bypass, arbitrary code execution, and privilege escalation to root.
  • CVE-2026-47871: High-severity directory traversal vulnerability.
  • CVE-2026-47870: High-severity privilege escalation vulnerability.
  • CVE-2026-47869: High-severity remote code execution vulnerability.

Patching and Risk Mitigation

Broadcom's official advisory does not indicate that any of these specific vulnerabilities have been exploited in the wild at this time. Despite the absence of confirmed malicious activity, the company advises that organizations should prioritize the installation of the latest updates. The potential for these flaws to be leveraged is elevated by the historical tendency for threat actors to exploit VMware product flaws during their operations.

Implications for Infrastructure Security

For IT and security teams, these disclosures underscore the necessity of maintaining a rigorous patching cadence for centralized management platforms like the Avi Load Balancer. Because these vulnerabilities could grant attackers deep access to the control plane or allow for privilege escalation, the exposure window directly impacts the integrity of the broader application environment. Relying on perimeter defenses alone is insufficient when software-defined platforms contain exploitable paths that allow attackers to bypass standard authentication, making prompt deployment of vendor patches a fundamental requirement for securing multi-cloud deployments.

#vmware#cybersecurity#vulnerability#patch management#broadcom

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories