logo

CVE-2026-47865: Critical Authentication Bypass in VMware Avi Load Balancer

ID: d5699b0b-832d-5efa-afe8-b488570b1cfe

STIX ID: report--d5699b0b-832d-5efa-afe8-b488570b1cfe

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-18

Date Updated: 2026-07-19

...
...

**CVE-2026-47865 — Authentication bypass in Broadcom/VMware Avi Load Balancer (CVSS 9.8).** An unauthenticated attacker with network access can completely bypass Control Plane authentication and obtain full confidentiality, integrity, and availability impact; affected versions include 22.1.1–22.1.7, 30.1.1–30.2.6, and 31.1.1–31.2.2, with patches available in 30.2.7 and 31.2.2-2p3. Broadcom recommends immediate patching (no workaround), restricting access until patched, and auditing logs for anomalous access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.