VMware sounds alarm on critical virtualization vulnerabilities

VMware released patches for various critical bugs affecting its multicloud application delivery platform.
Seven vulnerabilities in total were found in VMware Avi Load Balancer. The bugs range across authentication bypass vulnerability (CVE-2026-47865, CVE-2026-47866); remote code execution (CVE-2026-47867, CVE-2026-47869); and privilege escalation (CVE-2026-47868, CVE-2026-47870). Another exploit (CVE-2026-47871) was described as a directory traversal vulnerability in which attackers sidestep web server defenses to access restricted files outside a server's root folder.
Users were advised to upgrade to the latest version of the suite, VMware Avi Load Balancer 32.1.2. No in-the-wild exploitation of the bugs were reported by Broadcom.
Related Articles


