VMware Patches Multiple Critical Stored XSS Vulnerabilities
Key Takeaways Broadcom has issued patches for three critical stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and related VMware products. The flaws,...
Key Takeaways
- Broadcom has issued patches for three critical stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and related VMware products.
- The flaws, identified as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, each carry a CVSSv3 base score of 8.0, indicating “Important” severity.
- Exploitation requires an authenticated attacker with specific object-creation privileges to inject malicious scripts, potentially leading to administrative actions on behalf of other users.
- No workarounds are available, making immediate patching the sole remediation strategy.
Broadcom Addresses Critical Stored XSS Flaws in VMware Cloud Foundation Operations
Broadcom has announced the remediation of three significant stored cross-site scripting (XSS) vulnerabilities impacting VMware Cloud Foundation Operations and several associated VMware products. These critical flaws could allow authenticated attackers to embed malicious scripts, subsequently enabling them to execute administrative functions within compromised environments.
Table Of Content
The vulnerabilities, designated CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, were detailed in security advisory VMSA-2026-0004, released on June 8, 2026. Each vulnerability has been assigned a CVSSv3 base score of 8.0, categorizing them as “Important” in terms of severity. Broadcom has confirmed that no temporary workarounds are available, emphasizing that applying the provided patches is the only effective solution.
Understanding the Stored XSS Vulnerabilities
According to the advisory, the vulnerabilities in VMware Cloud Foundation Operations stem from insufficient sanitization of user-supplied input. This oversight allows for the persistence of malicious code within the system.
Stored XSS vulnerabilities are particularly concerning because, unlike their reflected counterparts, the malicious payload is saved on the server. This means the script executes every time an affected component is loaded by a victim, facilitating repeated attacks against multiple users over time.
The attack scenario outlined by Broadcom involves an attacker with privileges to create policies, views, or text-widgets. Such an actor could inject crafted scripts into these objects. When these objects are subsequently rendered within the management interface, the embedded scripts would execute in the context of other users, potentially including highly privileged administrators. This could enable the attacker to perform administrative actions, effectively achieving privilege escalation.
While successful exploitation necessitates pre-existing authenticated access with specific object-creation rights, the potential for privilege escalation within an operational platform managing virtualized infrastructure underscores the significant risk these vulnerabilities pose.
These vulnerabilities were responsibly reported to Broadcom by Alexis Bernazzani of Visa Inc. The comprehensive advisory covers a wide array of Broadcom virtualization products, including VMware Aria Operations, VMware Cloud Foundation Operations, VMware Cloud Foundation, VMware vSphere Foundation, and VMware Telco Cloud Platform.
Broadcom has released the necessary patches and updates, which organizations are strongly advised to apply in accordance with the provided Response Matrix:
| Product | Component | Affected Version | CVEs Addressed | Fixed Version |
|---|---|---|---|---|
| VMware Cloud Foundation / vSphere Foundation | VMware Cloud Foundation Operations | 9.1.x.x | CVE-2026-41722, CVE-2026-41723 | 9.1.0.0 |
| VMware Cloud Foundation / vSphere Foundation | VMware Cloud Foundation Operations | 9.0.x.x | CVE-2026-41722, CVE-2026-41723 | 9.0.2.0 EP2 |
| VMware Aria Operations | N/A | 8.x | CVE-2026-41722, CVE-2026-41723 | 8.18.6 |
| VMware Aria Operations | N/A | 8.x | CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 | 8.18.7 |
| VMware Cloud Foundation | VMware Aria Operations | 5.x | CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 | 8.18.7 |
| VMware Telco Cloud Platform | VMware Aria Operations | 5.x | CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 | KB443138 |
What You Should Do
- Immediately apply the listed fixed versions to all affected VMware products as detailed in the Broadcom security advisory VMSA-2026-0004.
- Review and tighten role-based access controls for creating policies, views, and text-widgets within your VMware environments. Limit these privileges to the absolute minimum necessary to reduce the attack surface.
- Monitor your systems for any unusual activity, especially related to administrative actions or script execution within the management interfaces of affected products.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.