Skip to content
VMware: Multiple products with stored cross-site scripting vulnerabilities

VMware: Multiple products with stored cross-site scripting vulnerabilities

Heise.De • June 8, 2026

Stored cross-site scripting vulnerabilities exist in VMware Cloud Foundation and related products. Attackers can use these to inject script code into victims.

In a security advisory, Broadcom warns the vulnerabilities. Several security vulnerabilities of this type are found in the virtualization software. The developers summarize it concisely: VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities. Attackers with rights to create policies, views, or text widgets can inject scripts, which are then executed as administrative actions in VMware Cloud Foundation Operations ( CVE-2026-41722 , CVE-2026-41723 , and CVE-2026-41724 ; all CVSS 8.0 , risk “ high ”).

A handful of VMware solutions are affected. VMware Cloud Foundation and vSphere Foundation from version 9.1.0 and 9.0.2.0 EP2, VMware Aria Operations 8.18.6, and VMware Cloud Foundation and VMware Aria Operations 8.18.7 are patched against the security vulnerabilities. For VMware Telco Cloud Platform, Broadcom provides a separate knowledge base article .

The vulnerabilities are apparently not yet being exploited in the wild, as Broadcom mentions nothing in this regard. There are no temporary workarounds that admins could implement as an interim solution. Only updating to the corrected software versions resolves the security issue. IT managers should not hesitate and should apply the updates promptly.

At the end of February, Broadcom had to close three security vulnerabilities in VMware Aria Operations and Cloud Foundation . Back then, attackers could also have injected and executed malicious code. However, those were different vulnerabilities that specifically allowed the injection of commands, the escalation of privileges within the system, and, in one case, also stored cross-site scripting.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.