37513
VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)
VCF Operations VCF Operations/Automation (formerly VMware Aria Suite) VMware Cloud Foundation VMware Telco Cloud Platform VMware vSphere Foundation
CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724
Multiple vulnerabilities in VMware Cloud Foundation Operations were privately reported to Broadcom. Patches and updates are available to remediate these vulnerabilities in affected Broadcom products.
Description: VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities. Broadcom has evaluated the severity of these issues to be in the Important severity range with a maximum CVSSv3 base score of 8.0 . Known Attack Vectors: A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
Resolution: To remediate CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Additional Documentation: None.
Acknowledgements: Broadcom would like to thank Alexis Bernazzani (Visa Inc.) for reporting these issues to us.
Response Matrix 3(a):
CVE-2026-41722, CVE-2026-41723
CVE-2026-41722, CVE-2026-41723
CVE-2026-41722, CVE-2026-41723
CVE-2026-41722, CVE-2026-41723, CVE-2026-41724
CVE-2026-41722, CVE-2026-41723, CVE-2026-41724
CVE-2026-41722, CVE-2026-41723, CVE-2026-41724
Fixed Version(s) and Release Notes:
VMware Cloud Foundation 9.1.0.0
Downloads and Documentation:
VMware vSphere Foundation 9.1.0.0 Downloads and Documentation:
VMware Cloud Foundation 9.0.2.0 EP2
Downloads and Documentation:
VMware vSphere Foundation 9.0.2.0 EP2
Downloads and Documentation:
VMware Aria Operations 8.18.7
Downloads and Documentation:
VMware Aria Operations 8.18.6 Downloads and Documentation:
VMware Cloud Foundation 5.x Downloads and Documentation:
VMware Telco Cloud Platform 5.x Downloads and Documentation
Mitre CVE Dictionary Links:
FIRST CVSSv3 Calculator: CVE-2026-41722: CVE-2026-41723: CVE-2026-41724:
2026-06-08: VMSA-2026-0004 Initial security advisory.
E-mail: [email protected] PGP key VMware Security Advisories VMware External Vulnerability Response and Remediation Policy VMware Lifecycle Support Phases VMware Security Blog X
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
