news.mlab.sh
Back to the feed
vulnerability

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer

High
Summary

Broadcom has released updates to patch seven critical and high-severity vulnerabilities in VMware Avi Load Balancer. These flaws could allow attackers to bypass authentication, execute code, and escalate privileges, posing a significant risk to organizations utilizing the product. While no in-the-wild exploitation has been reported, proactive patching is strongly recommended to mitigate potential attacks.

Broadcom announced on Tuesday that new VMware Avi Load Balancer updates address seven vulnerabilities, including several with high and critical severity ratings. VMware Avi Load Balancer is a software-defined platform used for load balancing, application security, and analytics within hybrid and multi-cloud environments. According to Broadcom, researchers Filip Waeytens of NATO’s technology and cyber hub and Lang Khuong Duy of Viettel IDC discovered these vulnerabilities. Waeytens identified CVE-2026-47865, a critical authentication bypass issue, while Duy found CVE-2026-47870 and CVE-2026-47871, which can lead to directory traversal attacks and privilege escalation, respectively. Both researchers also reported CVE-2026-47869, a high-severity remote code execution vulnerability. Broadcom’s advisory indicates that no in-the-wild exploitation has been detected for any of these vulnerabilities at the time of publication. However, given the potential for exploitation, organizations are urged to install the latest updates immediately to reduce the risk of attack.

Read the full article at SecurityWeek