VMware Security Updates – 15 July 2026

VMware has released security updates to fix several vulnerabilities affecting VMware Avi Load Balancer.

The addressed vulnerabilities could allow the attacker to perform directory traversal attacks, bypass security restrictions, gain elevated privileges, or inject and execute arbitrary code on the affected products.

Sample of the addressed vulnerabilities:

1. VMware Avi Load Balancer Authentication Bypass Vulnerability (CVE-2026- 47865):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security

2. VMware Avi Load Balancer Remote Code Execution Vulnerability (CVE-2026- 47867):

  • CVSS: 8.7
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Remote Code Execution
Vulnerabilities
  • CVE-2026-47865
  • CVE-2026-47866
  • CVE-2026-47867
  • CVE-2026-47868
  • CVE-2026-47869
  • CVE-2026-47870
  • CVE-2026-47871
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Updates

References