Vulnerability intelligence
CVE-2026-47865
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
CVSS Score
—
Critical
EPSS — Exploit Probability
0.8%
Riskier than 55% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
2 articles across 2 outlets · first covered Jul 14, 2026 · latest Jul 14, 2026
Tracked incidents
Coverage timeline
-
Broadcom patches Avi Load Balancer auth bypass CVE-2026-47865securityonline.info · Jul 14, 2026
-
Broadcom fixes critical VMware Avi LB flaws, CVE-2026-47865www.securityweek.com · Jul 14, 2026