Monday , July 27 2026
VMware

VMware Fixed Multiple Flaws Allow Attackers to Inject Malicious Scripts

Broadcom has revealed three stored cross-site scripting (XSS) flaws that affect VMware Cloud Foundation Operations and some other products. They warn that attackers who are logged in could add harmful scripts to do admin tasks in the system.

Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the issues were fixed in the security notice VMSA-2026-0004, released on June 8, 2026.

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

A new study from Beacom College shows that all automation scripts produced by top AI models like ChatGPT, Microsoft Copilot,...
Read More
Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Origin Energy Limited, a major energy provider in Australia, has said there was a cybersecurity issue with unauthorized access to...
Read More
Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Anthropic launched the Claude Security plugin in beta. This tool uses AI to find serious security flaws in Claude Code....
Read More
Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

ASUS has put out important security updates for a serious router flaw. This issue could let remote hackers run any...
Read More
Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

SolarWinds Patches 15 Critical Serv-U Flaws

SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix 15 problems that could let...
Read More
SolarWinds Patches 15 Critical Serv-U Flaws

Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were...
Read More
Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Zimbra has launched updates to fix serious security flaws, including a command injection bug in the SNMP monitoring part. As...
Read More
Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims' networks, says the cybersecurity firm...
Read More
Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

VMware Stored XSS Vulnerabilities

VMware Cloud Foundation Operations has several stored cross-site scripting flaws caused by not properly checking user input.

Stored XSS is more dangerous than reflected XSS because the harmful code stays on the server and runs every time a victim opens the affected part, allowing repeated attacks on many users.

The flaws were shared privately with Broadcom by Alexis Bernazzani from Visa Inc. The notice covers many Broadcom virtualization products, such as VMware Aria Operations, VMware Cloud Foundation Operations, VMware Cloud Foundation, VMware vSphere Foundation, and VMware Telco Cloud Platform. Broadcom has put out fixes and updates that companies should use based on the Response Matrix.

Product Component Affected Version CVEs Addressed Fixed Version
VMware Cloud Foundation / vSphere Foundation VMware Cloud Foundation Operations 9.1.x.x CVE-2026-41722, CVE-2026-41723 9.1.0.0
VMware Cloud Foundation / vSphere Foundation VMware Cloud Foundation Operations 9.0.x.x CVE-2026-41722, CVE-2026-41723 9.0.2.0 EP2
VMware Aria Operations N/A 8.x CVE-2026-41722, CVE-2026-41723 8.18.6
VMware Aria Operations N/A 8.x CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 8.18.7
VMware Cloud Foundation VMware Aria Operations 5.x CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 8.18.7
VMware Telco Cloud Platform VMware Aria Operations 5.x CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 KB443138

Administrators should prioritize applying the listed fixed versions promptly, given the absence of any workaround.

Organizations should check who has roles and limit permissions for making policies, views, and text-widgets. This will reduce the number of accounts that can cause these problems while fixes are being applied.

Check Also

Zimbra

Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Zimbra has launched updates to fix serious security flaws, including a command injection bug in …