Broadcom Fixes Critical VMware Stored XSS Bugs
ID: f6bfed8a-22f7-538a-ba5b-c1d1e03f93a1
STIX ID: report--f6bfed8a-22f7-538a-ba5b-c1d1e03f93a1
Feed Name: securityonline.info
Broadcom released an advisory for multiple stored XSS vulnerabilities in VMware Cloud Foundation operations affecting VMware Aria Operations, VMware Telco Cloud Platform, and vSphere Foundation (CVE-2026-41722, CVE-2026-41723, CVE-2026-41724). The flaws (CVSSv3 base up to 8.0) could allow a user with rights to create policies, views or text-widgets to inject scripts that perform administrative actions; Broadcom provides patches and administrators are urged to update immediately (Aria Operations fixed in 8.18.6).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
