VMware Cloud Foundation Operations Faces Multiple Stored XSS Vulnerabilities

VMware Cloud Foundation Operations Faces Multiple Stored XSS Vulnerabilities

First seen 8 Jun 2026, 12:47 UTC CybersecuritynewsHeise.DeGbhackerssupport.broadcom.comCcb.Belgium.Be+4 83% similarity 60.8

Article Content

Browse articles
ThreatCluster

Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities in VMware Cloud Foundation Operations and related products. The vulnerabilities, tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, allow authenticated attackers to inject malicious scripts that can perform administrative actions. These vulnerabilities have a CVSS score of 8.0, indicating a high severity level. Affected products include VMware Cloud Foundation and vSphere Foundation versions 9.1.0 and 9.0.2.0 EP2, as well as VMware Aria Operations. Broadcom advises that no active exploitation has been reported, but administrators should apply patches immediately to mitigate risks. There are no temporary workarounds available; only updates to the patched versions will resolve the issues. The vulnerabilities were privately reported and have been addressed in security advisory VMSA-2026-0004.

Key Points: • Three stored XSS vulnerabilities in VMware products allow script injection by authenticated users. • Affected products include VMware Cloud Foundation and vSphere Foundation versions 9.1.0 and 9.0.2.0 EP2. • Broadcom recommends immediate patching as there are no known workarounds for these vulnerabilities.

ThreatCluster AI

Timeline

2026-06-08
Broadcom discloses XSS vulnerabilities
Broadcom published security advisory VMSA-2026-0004 detailing three stored XSS vulnerabilities in VMware products, urging immediate patching.
support.broadcom.com
2026-06-08
CVE-2026-41722 published
CVE-2026-41722, a stored XSS vulnerability in VMware Cloud Foundation Operations, was published with a CVSS score of 8.0.
Heise.De
2026-06-08
CVE-2026-41723 published
CVE-2026-41723, another stored XSS vulnerability in VMware products, was disclosed alongside CVE-2026-41722 and CVE-2026-41724.
Cybersecuritynews
2026-06-08
CVE-2026-41724 published
CVE-2026-41724, the third stored XSS vulnerability affecting VMware Cloud Foundation Operations, was published with a high severity rating.
support.broadcom.com

Community

Browse all →