- Security updates have been released to address vulnerabilities in VM products.
- the vulnerabilities addressed are CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, which are stored cross-site scripting (stored XSS, a web vulnerability where input is saved and then executed on another user’s screen) vulnerabilities in VM Cloud Foundation Operations.
- the affected products are as follows
- CVE-2026-41722, CVE-2026-41723: VMware Cloud Foundation version 9.1.x.x, 9.0.x.x, VMware vSphere Foundation version 9.1.x.x, 9.0.x.x, VMware Aria Operations version 8.x, VM Cloud Foundation version 5.x, VM Telco Cloud Platform version 5.x.
- CVE-2026-41724: VM Aria Operations version 8.x, VMware Cloud Foundation version 5.x, VMware Telco Cloud Platform version 5.x.
- vulnerability patches have been made available in the latest updates.
- the patch versions are: VMware Cloud Foundation 9.1.0.0, VMware Cloud Foundation 9.0.2.0 EP2, VMware vSphere Foundation 9.1.0.0, VMware vSphere Foundation 9.0.2.0 EP2, VMware Aria Operations 8.18.6, VMware Cloud Foundation 8.18.7, and VMware Telco Cloud Platform KB443138 for CVE-2026-41722 and CVE-2026-41723.
- For CVE-2026-41724, it is VM Aria Operations 8.18.7, VMware Cloud Foundation 8.18.7, VMware Telco Cloud Platform KB443138.
- the reference document is VMSA-2026-0004.