CVE-2026-47869: Second RCE Code Injection Path in VMware Avi Load Balancer
ID: 8646f135-eab5-53f7-98d8-9db94865eb28
STIX ID: report--8646f135-eab5-53f7-98d8-9db94865eb28
Feed Name: CosmicBytez Labs
### Executive Summary CVE-2026-47869 is a network-reachable code-injection vulnerability (CWE-94) in the Avi Load Balancer Control Plane rated CVSS 8.7 (High). Multiple version ranges are affected (22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2, 32.1.1) and Broadcom provides patched releases (30.2.7, 31.2.2-2p3, 32.1.2); when chained with other disclosed CVEs, it can result in an effective unauthenticated RCE, so immediate patching and isolation of Control Plane access are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
