VMware Product Security Update Advisory

VMware Product Security Update Advisory

Overview


A security update has been released to address a vulnerability in a VMware product. The affected product is VMware Avi Load Balancer, and users of this version are advised to update to the latest version.

Affected Products and Versions


  • CVE-2026-47865 affects VMware Avi Load Balancer versions 22.1.1 Through 22.1.7, 30.1.1 Through 30.2.6, 31.1.1 Through 31.2.2.
  • CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871 affect VMware Avi Load Balancer versions 22.1.1 Through 22.1.7, 30.1.1 Through 30.2.6, 31.1.1 Through 31.2.2, And 32.1.1.

Resolved Vulnerabilities


  • CVE-2026-47865: Authentication bypass vulnerability.
  • CVE-2026-47866: Authorization bypass vulnerability.
  • CVE-2026-47867: Remote code execution vulnerability.
  • CVE-2026-47868: Local privilege escalation vulnerability.
  • CVE-2026-47869: Remote code execution vulnerability.
  • CVE-2026-47870: Privilege escalation vulnerability.
  • CVE-2026-47871: Directory traversal vulnerability.

Patch Information


Vulnerability Patches have been provided in the latest update. Please update to the following versions as indicated on the reference site.

  • CVE-2026-47865 Fixed in versions: 30.2.7, 31.2.2-2P3.
  • CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871: 30.2.7, 31.2.2-2P3, 32.1.2.

Note


  • VMSA-2026-0005: VMware Avi Load Balancer addresses multiple vulnerabilities.