CVE-2026-47867: Broadcom VMware Avi Load Balancer
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
Affected products
- Broadcom VMware Avi Load Balancer: from 22.1.1, up to and including 22.1.7; from 30.1.1, before 30.2.7 (fixed in 30.2.7); from 31.1.1, before 31.2.2 (fixed in 31.2.2); version 31.2.2 only; version 32.1.1 only
Published 2026-07-18. Last modified 2026-08-20.