Skip to content

3 high Cross-Site Scripting (XSS) in VMware (Telco) Cloud/vSphere Foundation & Aria ...

Ccb.Belgium.Be • June 8, 2026

VMware Cloud Foundation is Broadcom’s private-cloud platform that bundles vSphere and cloud management to run and manage modern workloads in hybrid environments. VMware vSphere Foundation is a lighter bundle centered on vSphere while Aria Operations is the monitoring and analytics layer that tracks performance, capacity, and operational health across VMware environments.

According to Broadcom, three high-criticality, cross-site scripting (XSS) vulnerabilities (CVE-2026-41722, CVE-2026-41723, CVE-2026-41724) are affecting multiple versions of VMware (Telco) Cloud & vSphere Foundation, and Aria Operations.

As of the writing of this advisory (2026-06-08), there is no information a publicly available proof-of-concept or active exploitation of any of the three vulnerabilities.

If any of the vulnerabilities are exploited, that can have a high impact in all three aspects of the CIA triad (Confidentiality, Integrity, Availability).

CVE-2026-41722, CVE-2026-41723, CVE-2026-41724: An authenticated, remote threat actor with a role with (at least) low privileges and with some user interaction can exploit this vulnerability to inject malicious scripts that are within policies, views, or text-widgets that they created. The required user interaction is viewing those objects (policies/views/texts) as this can trigger the execution of the malicious scripts which will allow the attacker to perform administrative actions.

The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority, after thorough testing.

Ensure you update to (those versions or later) VMware Cloud Foundation / VMware vSphere Foundation version 9.1.0.0, or 9.0.2.0 EP2, VMware Aria Operations 8.18.7, VMware Telco Cloud Platform KB443138 ( ).

For details, see Broadcom’s advisory: .

The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity, ensuring a swift response in case of an intrusion.

In case of an intrusion, you can report an incident via: .

While patching appliances or software to the newest version may provide safety from future exploitation, it does not remediate historic compromise.