Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Vanta Stealer Drains Browser, Crypto, and Gaming Accounts
August 6, 2026
Critical Flaws in Anthropic, Google, OpenAI Coding Agents Allow RCE
August 6, 2026
Home/CyberSecurity News/VMware Patches Multiple Critical Stored XSS Vulnerabilities
CyberSecurity News

VMware Patches Multiple Critical Stored XSS Vulnerabilities

Key Takeaways Broadcom has issued patches for three critical stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and related VMware products. The flaws,...

Emy Elsamnoudy
Emy Elsamnoudy
June 8, 2026 3 Min Read
50 0

Key Takeaways

  • Broadcom has issued patches for three critical stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and related VMware products.
  • The flaws, identified as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, each carry a CVSSv3 base score of 8.0, indicating “Important” severity.
  • Exploitation requires an authenticated attacker with specific object-creation privileges to inject malicious scripts, potentially leading to administrative actions on behalf of other users.
  • No workarounds are available, making immediate patching the sole remediation strategy.

Broadcom Addresses Critical Stored XSS Flaws in VMware Cloud Foundation Operations

Broadcom has announced the remediation of three significant stored cross-site scripting (XSS) vulnerabilities impacting VMware Cloud Foundation Operations and several associated VMware products. These critical flaws could allow authenticated attackers to embed malicious scripts, subsequently enabling them to execute administrative functions within compromised environments.

Table Of Content

  • Key Takeaways
  • Broadcom Addresses Critical Stored XSS Flaws in VMware Cloud Foundation Operations
  • Understanding the Stored XSS Vulnerabilities
  • What You Should Do

The vulnerabilities, designated CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, were detailed in security advisory VMSA-2026-0004, released on June 8, 2026. Each vulnerability has been assigned a CVSSv3 base score of 8.0, categorizing them as “Important” in terms of severity. Broadcom has confirmed that no temporary workarounds are available, emphasizing that applying the provided patches is the only effective solution.

Understanding the Stored XSS Vulnerabilities

According to the advisory, the vulnerabilities in VMware Cloud Foundation Operations stem from insufficient sanitization of user-supplied input. This oversight allows for the persistence of malicious code within the system.

Stored XSS vulnerabilities are particularly concerning because, unlike their reflected counterparts, the malicious payload is saved on the server. This means the script executes every time an affected component is loaded by a victim, facilitating repeated attacks against multiple users over time.

The attack scenario outlined by Broadcom involves an attacker with privileges to create policies, views, or text-widgets. Such an actor could inject crafted scripts into these objects. When these objects are subsequently rendered within the management interface, the embedded scripts would execute in the context of other users, potentially including highly privileged administrators. This could enable the attacker to perform administrative actions, effectively achieving privilege escalation.

While successful exploitation necessitates pre-existing authenticated access with specific object-creation rights, the potential for privilege escalation within an operational platform managing virtualized infrastructure underscores the significant risk these vulnerabilities pose.

These vulnerabilities were responsibly reported to Broadcom by Alexis Bernazzani of Visa Inc. The comprehensive advisory covers a wide array of Broadcom virtualization products, including VMware Aria Operations, VMware Cloud Foundation Operations, VMware Cloud Foundation, VMware vSphere Foundation, and VMware Telco Cloud Platform.

Broadcom has released the necessary patches and updates, which organizations are strongly advised to apply in accordance with the provided Response Matrix:

Product Component Affected Version CVEs Addressed Fixed Version
VMware Cloud Foundation / vSphere Foundation VMware Cloud Foundation Operations 9.1.x.x CVE-2026-41722, CVE-2026-41723 9.1.0.0
VMware Cloud Foundation / vSphere Foundation VMware Cloud Foundation Operations 9.0.x.x CVE-2026-41722, CVE-2026-41723 9.0.2.0 EP2
VMware Aria Operations N/A 8.x CVE-2026-41722, CVE-2026-41723 8.18.6
VMware Aria Operations N/A 8.x CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 8.18.7
VMware Cloud Foundation VMware Aria Operations 5.x CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 8.18.7
VMware Telco Cloud Platform VMware Aria Operations 5.x CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 KB443138

What You Should Do

  • Immediately apply the listed fixed versions to all affected VMware products as detailed in the Broadcom security advisory VMSA-2026-0004.
  • Review and tighten role-based access controls for creating policies, views, and text-widgets within your VMware environments. Limit these privileges to the absolute minimum necessary to reduce the attack surface.
  • Monitor your systems for any unusual activity, especially related to administrative actions or script execution within the management interfaces of affected products.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

UniFi OS Server Critical RCE Chain Lets Attackers Gain Root Access Without Credentials

Next Post

Critical IE WebBrowser Control Flaw Lets Attackers Get RCE

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Paperclip Flaws Let Attackers Gain Admin Access
August 6, 2026
Fake Movie Download Exposes Passwords, Payments, Crypto Assets
August 6, 2026
Critical Oracle Solaris CVE-2024-21013 Flaw Lets Attackers Remotely Control Servers
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us