CVE-2026-47865: Broadcom VMware Avi Load Balancer
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected products
- Broadcom VMware Avi Load Balancer: from 22.1.1, before 22.1.7 (fixed in 22.1.7); from 30.1.1, before 30.2.7 (fixed in 30.2.7); from 31.1.1, before 31.2.2 (fixed in 31.2.2); version 22.1.7 only; version 31.2.2 only; version 32.1.1 only
Published 2026-07-18. Last modified 2026-08-20.