← All stories
● Covered by 1 source · 1 reportHigh impact

VMware Avi Load Balancer Patches 7 Critical Vulnerabilities

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Seven vulnerabilities patched in VMware Avi Load Balancer
  • Includes critical authentication bypass and remote code execution
  • Network access required for exploitation of most flaws

Summary of the Vulnerabilities

Broadcom has announced that VMware Avi Load Balancer has been updated to address seven serious vulnerabilities. Among them are critical authentication bypass issues and high-severity flaws allowing arbitrary code execution and privilege escalation.

Two external researchers, Filip Waeytens and Lang Khuong Duy, reported these vulnerabilities following security assessments.

Details on Each Vulnerability

CVE-2026-47865, discovered by Filip Waeytens, is a critical authentication bypass vulnerability that could let attackers breach the Avi control plane.

Waeytens also found three additional high-severity vulnerabilities: CVE-2026-47866, CVE-2026-47867, and CVE-2026-47868, which involve bypassing authentication, executing arbitrary code, and escalating privileges. These require either network or local access for exploitation.

Lang Khuong Duy identified two more high-severity vulnerabilities: CVE-2026-47871 for directory traversal attacks and CVE-2026-47870 for privilege escalation.

Potential Impact and Importance of Updating

The advisory from Broadcom states there are currently no reported in-the-wild exploitations of these vulnerabilities. However, the company emphasizes the critical nature of installing the latest updates to mitigate risks.

Given the history of attacks targeting VMware products, organizations should prioritize these updates.

Conclusion

With seven vulnerabilities patched in VMware Avi Load Balancer, it is essential for organizations to remain vigilant and apply updates promptly. The nature of these vulnerabilities highlights the need for ongoing security assessments and monitoring of enterprise environments.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Broadcom announced patches for seven vulnerabilities in VMware Avi Load Balancer, including critical authentication bypass and remote code execution issues. Organizations are advised to update promptly to prevent potential exploitation, especially as VMware flaws have been targeted in past attacks.