Broadcom patches seven serious VMware Avi Load Balancer flaws, including auth bypass and remote code execution bugs

Broadcom released updates for VMware Avi Load Balancer to fix seven serious security flaws that could let attackers break into or take control of affected systems. The issues include critical authentication bypass CVE-2026-47865, high-severity flaws CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, and CVE-2026-47871, enabling authentication bypass, remote code execution, privilege escalation to root, and directory traversal. Broadcom said there is no reported in-the-wild exploitation in the advisory.
Why it matters: Organizations using VMware Avi Load Balancer for application delivery and security should update promptly because several of these bugs could let a network-accessible attacker bypass login protections or gain elevated control. For defenders, this is a straightforward patch-now advisory even without confirmed active exploitation.

Sources

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
Eduard Kovacs 2026.07.14 100% relevant
This article appears to be the first item here establishing the specific July 2026 Broadcom patch release for the seven VMware Avi Load Balancer CVEs.
← Back to all stories