Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts
ID: 6e32d67e-3b8f-522f-bdf7-c29e5a2494ed
STIX ID: report--6e32d67e-3b8f-522f-bdf7-c29e5a2494ed
Feed Name: GBHackers
VMware disclosed three high-severity stored XSS vulnerabilities (CVE-2026-41722/41723/41724) in VMware Cloud Foundation Operations (VMSA-2026-0004) with a combined CVSS v3 score of 8.0; these flaws allow attackers to store malicious JavaScript that can execute in administrators' browsers, risking session hijacking, token theft, configuration changes, and broader impact across integrated VMware components. No workarounds exist, so affected organizations are strongly advised to apply vendor patches immediately and strengthen access controls and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
