Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
152 Chrome Extensions Maliciously Hide Ad Tracking
June 14, 2026
Maine AG Takes Data Breach Portal Offline After Fake
June 14, 2026
Agentjacking Attack Hijacks AI Coding Agent for Mal
June 13, 2026
Home/CyberSecurity News/Multiple VMware Stored XSS Vulnerabilities Allow Attackers to
CyberSecurity News

Multiple VMware Stored XSS Vulnerabilities Allow Attackers to

Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities impacting VMware Cloud Foundation Operations and various related products. The company warns that authenticated...

Emy Elsamnoudy
Emy Elsamnoudy
June 8, 2026 2 Min Read
17 0

Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities impacting VMware Cloud Foundation Operations and various related products. The company warns that authenticated attackers could exploit these flaws by injecting malicious scripts, enabling them to perform administrative actions within affected environments.

Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the flaws were addressed in security advisory VMSA-2026-0004, published on June 8, 2026.

Each vulnerability carries a CVSSv3 base score of 8.0, placing the issues in the “Important” severity range. No workarounds are available, making patching the only viable remediation path.

VMware Stored XSS Vulnerabilities

According to the advisory, VMware Cloud Foundation Operations contains multiple stored cross-site scripting weaknesses introduced through improperly sanitized user-controlled input.

Stored XSS is particularly dangerous compared to reflected variants because the malicious payload is persisted server-side and executed whenever a victim loads the affected component, enabling repeatable attacks against multiple users.

The advisory outlines a clear attack path. A malicious actor holding privileges to create policies, views, or text-widgets could embed crafted scripts into these objects.

When rendered in the management interface, those scripts execute in the context of other users, potentially higher-privileged administrators, allowing the attacker to carry out administrative actions on their behalf.

While exploitation requires existing authenticated access with object-creation rights, the privilege escalation potential within an operations platform that oversees virtualized infrastructure makes the risk significant.

The vulnerabilities were privately reported to Broadcom by Alexis Bernazzani of Visa Inc. The advisory spans a broad set of Broadcom virtualization products, including VMware Aria Operations, VMware Cloud Foundation Operations, VMware Cloud Foundation, VMware vSphere Foundation, and VMware Telco Cloud Platform.

Broadcom has released patches and updates that organizations should apply according to the Response Matrix.

Product Component Affected Version CVEs Addressed Fixed Version
VMware Cloud Foundation / vSphere Foundation VMware Cloud Foundation Operations 9.1.x.x CVE-2026-41722, CVE-2026-41723 9.1.0.0
VMware Cloud Foundation / vSphere Foundation VMware Cloud Foundation Operations 9.0.x.x CVE-2026-41722, CVE-2026-41723 9.0.2.0 EP2
VMware Aria Operations N/A 8.x CVE-2026-41722, CVE-2026-41723 8.18.6
VMware Aria Operations N/A 8.x CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 8.18.7
VMware Cloud Foundation VMware Aria Operations 5.x CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 8.18.7
VMware Telco Cloud Platform VMware Aria Operations 5.x CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 KB443138

Administrators should prioritize applying the listed fixed versions promptly, given the absence of any workaround.

Organizations are also advised to review role assignments and tighten permissions for creating policies, views, and text-widgets, limiting the pool of accounts capable of triggering these vulnerabilities while patches are rolled out.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical RCE in UniFi OS Server Grants Root Access

Next Post

IE WebBrowser Control Attack Chain: Clicks Lead to R

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Government Directive Blocks Anthropic Fable 5 & Mythos Access
June 13, 2026
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us