CVE-2026-47865: Broadcom VMware Avi Load Balancer

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

Affected products

  • Broadcom VMware Avi Load Balancer: from 22.1.1, before 22.1.7 (fixed in 22.1.7); from 30.1.1, before 30.2.7 (fixed in 30.2.7); from 31.1.1, before 31.2.2 (fixed in 31.2.2); version 22.1.7 only; version 31.2.2 only; version 32.1.1 only

Published 2026-07-18. Last modified 2026-08-20.