news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans les produits VMware (07 septembre 2026)

CriticalCVSS 9.8
Summary

Multiple vulnerabilities have been discovered in VMware products, potentially allowing an attacker to cause a security issue. These vulnerabilities are present in RabbitMQ and Tanzu for Valkey. Users are advised to refer to the VMware security advisories for details on how to obtain and apply the necessary fixes.

Multiple vulnerabilities have been identified within VMware products, requiring immediate attention. These vulnerabilities impact RabbitMQ and Tanzu for Valkey, potentially enabling an attacker to trigger a security incident. The CERT-FR report details a comprehensive list of CVEs associated with these issues.

**What happened**

Several vulnerabilities exist within RabbitMQ versions 4.0.x (prior to 4.0.24), 4.1.x (prior to 4.1.15), 4.2.x (prior to 4.2.10), 4.3.x (prior to 4.3.5), and any version prior to 3.13.19. Additionally, vulnerabilities have been found in Tanzu for Valkey on Kubernetes versions prior to 13.5.0. The specific details of these vulnerabilities are outlined in the linked VMware security advisories. The CERT-FR report indicates that these vulnerabilities could be exploited to cause a security problem, though the exact nature of the issue is not fully specified.

**Technical details** The following CVEs are associated with these vulnerabilities: CVE-2024-11053, CVE-2024-31227, CVE-2024-31228, CVE-2024-31449, CVE-2024-46981, CVE-2024-51741, CVE-2026-11856, CVE-2026-13757, CVE-2026-1965, CVE-2026-33818, CVE-2026-35469, CVE-2026-3783, CVE-2026-3784, CVE-2026-39822, CVE-2026-41989, CVE-2026-42505, CVE-2026-46600, CVE-2026-4873, CVE-2026-48864, CVE-2026-5435, CVE-2026-54369, CVE-2026-54370, CVE-2026-54572, CVE-2026-5545, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865, CVE-2026-5773, CVE-2026-58016, CVE-2026-5928, CVE-2026-59732, CVE-2026-59733, CVE-2026-6238, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-67412, CVE-2026-67414, CVE-2026-67416, CVE-2026-67418, CVE-2026-67419, CVE-2026-67420, CVE-2026-67421, CVE-2026-71309, CVE-2026-71311, CVE-2026-71312, CVE-2026-71313, CVE-2026-7168, CVE-2026-8286, CVE-2026-84304, CVE-2026-8458, CVE-2026-8924, CVE-2026-8927, CVE-2026-8932, CVE-2026-9547.

**Impact**

The potential impact of these vulnerabilities is a security breach, allowing an attacker to exploit the system and potentially gain unauthorized access or control. The exact nature of the exploitation is not fully detailed, but the presence of numerous CVEs highlights a significant security risk. The vulnerabilities could be used to compromise RabbitMQ instances and Tanzu for Valkey deployments.

**What to do**

Users are strongly advised to refer to the linked VMware security advisories for detailed instructions on how to apply the necessary patches and updates. Specifically, VMware recommends updating RabbitMQ and Tanzu for Valkey to the latest versions. Regularly monitoring security advisories and applying updates promptly is crucial for maintaining a secure environment.

**Why it matters**

These vulnerabilities represent a serious security risk for organizations utilizing VMware products. Prompt remediation is essential to minimize the potential impact of a successful attack. The large number of CVEs underscores the importance of proactive security practices and diligent vulnerability management.

Read the full article at CERT-FR