Heise.De
VMware Cloud Foundation Operations Faces Multiple Stored XSS Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities in VMware Cloud Foundation Operations and related products. The vulnerabilities, tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, allow authenticated attackers to inject malicious scripts that can perform administrative actions. These vulnerabilities have a CVSS score of 8.0, indicating a high severity level. Affected products include VMware Cloud Foundation and vSphere Foundation versions 9.1.0 and 9.0.2.0 EP2, as well as VMware Aria Operations. Broadcom advises that no active exploitation has been reported, but administrators should apply patches immediately to mitigate risks. There are no temporary workarounds available; only updates to the patched versions will resolve the issues. The vulnerabilities were privately reported and have been addressed in security advisory VMSA-2026-0004.
Key Points: • Three stored XSS vulnerabilities in VMware products allow script injection by authenticated users. • Affected products include VMware Cloud Foundation and vSphere Foundation versions 9.1.0 and 9.0.2.0 EP2. • Broadcom recommends immediate patching as there are no known workarounds for these vulnerabilities.