logo

Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts

ID: 6e32d67e-3b8f-522f-bdf7-c29e5a2494ed

STIX ID: report--6e32d67e-3b8f-522f-bdf7-c29e5a2494ed

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Divya

...
...

VMware disclosed three high-severity stored XSS vulnerabilities (CVE-2026-41722/41723/41724) in VMware Cloud Foundation Operations (VMSA-2026-0004) with a combined CVSS v3 score of 8.0; these flaws allow attackers to store malicious JavaScript that can execute in administrators' browsers, risking session hijacking, token theft, configuration changes, and broader impact across integrated VMware components. No workarounds exist, so affected organizations are strongly advised to apply vendor patches immediately and strengthen access controls and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.