

VMware Avi Load Balancer versions 22.1.1 through 32.1.1, running on any platform. All seven CVEs affect versions 22.1.1 through 31.2.2; six of the seven also affect version 32.1.1.
Broadcom disclosed seven vulnerabilities in VMware Avi Load Balancer spanning authentication bypass, remote code execution, local privilege escalation, and directory traversal. The most severe vulnerability, CVE-2026-47865 (CVSS 9.8), allows an unauthenticated attacker with network access to bypass authentication entirely and gain access to the Avi Control Plane. Two additional RCE vulnerabilities and a directory traversal flaw compound the risk for any organisation running an exposed instance.
Advisories published 14 July 2026. No active exploitation confirmed at time of publication. Fixed versions are available for all affected release branches. The recommended remediation window is ten working days; given the critical CVSS scores and the presence of unauthenticated attack vectors, organisations should prioritise patching immediately.
The Avi Control Plane management interface accessible over the network. CVE-2026-47865 requires no authentication. CVE-2026-47867 and CVE-2026-47869 require network access but may be reachable by unauthenticated or authenticated users respectively. CVE-2026-47868 requires local access. CVE-2026-47871 requires authentication. Any deployment where the Avi Control Plane is internet-exposed or reachable from untrusted network segments is at elevated risk.
CVE-2026-47865 allows a network-adjacent unauthenticated attacker to bypass authentication and gain full access to the Avi Control Plane, the central management interface governing load balancer policy and configuration. CVE-2026-47867 and CVE-2026-47869 enable remote code execution on the Control Plane, allowing an attacker to execute arbitrary commands on the underlying system. CVE-2026-47868 enables local privilege escalation to root. CVE-2026-47871 allows an authenticated attacker to perform directory traversal and access files outside intended boundaries. Combined, these vulnerabilities represent a path from unauthenticated network access to full system compromise.
Risk is rated High across all organisation sizes in both government and commercial sectors. VMware Avi Load Balancer is a core infrastructure component in enterprise environments; compromise of the Control Plane gives an attacker the ability to manipulate traffic routing, intercept application traffic, and pivot into connected systems. The presence of a CVSS 9.8 unauthenticated authentication bypass makes this advisory high priority regardless of whether active exploitation has been confirmed.
Upgrade VMware Avi Load Balancer to the following fixed versions as soon as operationally feasible:
Version 32.1.1: Upgrade to 32.1.2 (fixes CVE-2026-47866 through CVE-2026-47871; CVE-2026-47865 not present in this branch).
Versions 31.1.1 through 31.2.2: Upgrade to 31.2.2-2p3.
Versions 30.2.1 through 30.2.6: Upgrade to 30.2.7.
Versions 22.1.1 through 22.1.7: Upgrade to 30.2.7.
No workarounds are documented. Where immediate patching is not possible, restrict network access to the Avi Control Plane to trusted management networks only and ensure it is not internet-exposed.
Apply the Principle of Least Privilege across all Avi Load Balancer administrative accounts and review permissions regularly. Use vulnerability management tooling to identify all affected instances across the estate and track remediation status. Ensure endpoint and perimeter security products carry the latest signatures to detect exploitation attempts. Monitor Control Plane access logs for anomalous authentication activity, unexpected administrative actions, or configuration changes that cannot be attributed to known change management activity.
Broadcom Support Portal - VMSA-2026-0005. CVEs: CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




