logo

CVE-2026-47869: Second RCE Code Injection Path in VMware Avi Load Balancer

ID: 8646f135-eab5-53f7-98d8-9db94865eb28

STIX ID: report--8646f135-eab5-53f7-98d8-9db94865eb28

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-18

Date Updated: 2026-07-19

...
...

### Executive Summary CVE-2026-47869 is a network-reachable code-injection vulnerability (CWE-94) in the Avi Load Balancer Control Plane rated CVSS 8.7 (High). Multiple version ranges are affected (22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2, 32.1.1) and Broadcom provides patched releases (30.2.7, 31.2.2-2p3, 32.1.2); when chained with other disclosed CVEs, it can result in an effective unauthenticated RCE, so immediate patching and isolation of Control Plane access are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.