VMware Product Security Update Advisory
Overview
A security update has been released to address a vulnerability in a VMware product. The affected product is VMware Avi Load Balancer, and users of this version are advised to update to the latest version.
Affected Products and Versions
- CVE-2026-47865 affects VMware Avi Load Balancer versions 22.1.1 Through 22.1.7, 30.1.1 Through 30.2.6, 31.1.1 Through 31.2.2.
- CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871 affect VMware Avi Load Balancer versions 22.1.1 Through 22.1.7, 30.1.1 Through 30.2.6, 31.1.1 Through 31.2.2, And 32.1.1.
Resolved Vulnerabilities
- CVE-2026-47865: Authentication bypass vulnerability.
- CVE-2026-47866: Authorization bypass vulnerability.
- CVE-2026-47867: Remote code execution vulnerability.
- CVE-2026-47868: Local privilege escalation vulnerability.
- CVE-2026-47869: Remote code execution vulnerability.
- CVE-2026-47870: Privilege escalation vulnerability.
- CVE-2026-47871: Directory traversal vulnerability.
Patch Information
Vulnerability Patches have been provided in the latest update. Please update to the following versions as indicated on the reference site.
- CVE-2026-47865 Fixed in versions: 30.2.7, 31.2.2-2P3.
- CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871: 30.2.7, 31.2.2-2P3, 32.1.2.
Note
- VMSA-2026-0005: VMware Avi Load Balancer addresses multiple vulnerabilities.