logo

Broadcom Fixes Critical VMware Stored XSS Bugs

ID: f6bfed8a-22f7-538a-ba5b-c1d1e03f93a1

STIX ID: report--f6bfed8a-22f7-538a-ba5b-c1d1e03f93a1

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Do Son

...
...

Broadcom released an advisory for multiple stored XSS vulnerabilities in VMware Cloud Foundation operations affecting VMware Aria Operations, VMware Telco Cloud Platform, and vSphere Foundation (CVE-2026-41722, CVE-2026-41723, CVE-2026-41724). The flaws (CVSSv3 base up to 8.0) could allow a user with rights to create policies, views or text-widgets to inject scripts that perform administrative actions; Broadcom provides patches and administrators are urged to update immediately (Aria Operations fixed in 8.18.6).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.