{"id":13453,"date":"2026-06-08T10:03:45","date_gmt":"2026-06-08T10:03:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/08\/multiple-vmware-stored-xss-vulnerabilities-allow-attackers-to-inject-malicious-scripts\/"},"modified":"2026-06-08T10:03:45","modified_gmt":"2026-06-08T10:03:45","slug":"multiple-vmware-stored-xss-vulnerabilities-allow-attackers-to-inject-malicious-scripts","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/08\/multiple-vmware-stored-xss-vulnerabilities-allow-attackers-to-inject-malicious-scripts\/","title":{"rendered":"Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts"},"content":{"rendered":"<p>    Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to perform administrative actions within the environment.<\/p>\n<p class=\"wp-block-paragraph\">Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the flaws were addressed in security advisory VMSA-2026-0004, published on June 8, 2026.<\/p>\n<p class=\"wp-block-paragraph\">Each vulnerability carries a CVSSv3 base score of 8.0, placing the issues in the \u201cImportant\u201d severity range. No workarounds are available, making patching the only viable remediation path.<\/p>\n<h2 id=\"h-vmware-stored-xss-vulnerabilities\" class=\"wp-block-heading\"><strong>VMware Stored XSS Vulnerabilities<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">According to the advisory, <a href=\"https:\/\/cybersecuritynews.com\/vmware-tools-and-aria-operations-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">VMware Cloud Foundation Operations<\/a> contains multiple stored cross-site scripting weaknesses introduced through improperly sanitized user-controlled input.<\/p>\n<p class=\"wp-block-paragraph\">Stored XSS is particularly dangerous compared to reflected variants because the malicious payload is persisted server-side and executed whenever a victim loads the affected component, enabling repeatable attacks against multiple users.<\/p>\n<p class=\"wp-block-paragraph\">The advisory outlines a clear attack path. A malicious actor holding privileges to create policies, views, or text-widgets could embed crafted scripts into these objects.<\/p>\n<p class=\"wp-block-paragraph\">When rendered in the management interface, those scripts execute in the context of other users, potentially higher-privileged administrators, allowing the attacker to carry out administrative actions on their behalf.<\/p>\n<p class=\"wp-block-paragraph\">While exploitation requires existing authenticated access with object-creation rights, the privilege escalation potential within an operations platform that oversees virtualized infrastructure makes the risk significant.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerabilities were privately reported to Broadcom by Alexis Bernazzani of Visa Inc. <a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37513\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The advisory spans<\/a> a broad set of Broadcom virtualization products, including VMware Aria Operations, VMware Cloud Foundation Operations, VMware Cloud Foundation, VMware vSphere Foundation, and VMware Telco Cloud Platform. <\/p>\n<p class=\"wp-block-paragraph\">Broadcom has released patches and updates that organizations should apply according to the Response Matrix.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Product<\/th>\n<th>Component<\/th>\n<th>Affected Version<\/th>\n<th>CVEs Addressed<\/th>\n<th>Fixed Version<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>VMware Cloud Foundation \/ vSphere Foundation<\/td>\n<td>VMware Cloud Foundation Operations<\/td>\n<td>9.1.x.x<\/td>\n<td>CVE-2026-41722, CVE-2026-41723<\/td>\n<td>9.1.0.0<\/td>\n<\/tr>\n<tr>\n<td>VMware Cloud Foundation \/ vSphere Foundation<\/td>\n<td>VMware Cloud Foundation Operations<\/td>\n<td>9.0.x.x<\/td>\n<td>CVE-2026-41722, CVE-2026-41723<\/td>\n<td>9.0.2.0 EP2<\/td>\n<\/tr>\n<tr>\n<td>VMware Aria Operations<\/td>\n<td>N\/A<\/td>\n<td>8.x<\/td>\n<td>CVE-2026-41722, CVE-2026-41723<\/td>\n<td>8.18.6<\/td>\n<\/tr>\n<tr>\n<td>VMware Aria Operations<\/td>\n<td>N\/A<\/td>\n<td>8.x<\/td>\n<td>CVE-2026-41722, CVE-2026-41723, CVE-2026-41724<\/td>\n<td>8.18.7<\/td>\n<\/tr>\n<tr>\n<td>VMware Cloud Foundation<\/td>\n<td>VMware Aria Operations<\/td>\n<td>5.x<\/td>\n<td>CVE-2026-41722, CVE-2026-41723, CVE-2026-41724<\/td>\n<td>8.18.7<\/td>\n<\/tr>\n<tr>\n<td>VMware Telco Cloud Platform<\/td>\n<td>VMware Aria Operations<\/td>\n<td>5.x<\/td>\n<td>CVE-2026-41722, CVE-2026-41723, CVE-2026-41724<\/td>\n<td>KB443138<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Administrators should prioritize applying the listed fixed versions promptly, given the absence of any workaround.<\/p>\n<p class=\"wp-block-paragraph\">Organizations are also advised to review role assignments and tighten permissions for creating policies, views, and text-widgets, limiting the pool of accounts capable of triggering these vulnerabilities while patches are rolled out.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/vmware-stored-xss-vulnerabilities\/\">Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/vmware-stored-xss-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to perform administrative actions within the environment. Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the flaws were addressed in [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-13453","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13453"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13453"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13453\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}