Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical VMware XSS Vulnerabilities Exposed

Critical VMware XSS Vulnerabilities Exposed

Posted on June 8, 2026 By CWS

Broadcom has recently reported three critical stored cross-site scripting (XSS) vulnerabilities impacting several VMware products, including VMware Cloud Foundation Operations. These security flaws enable authenticated attackers to insert harmful scripts capable of executing administrative tasks within the affected environment.

Details of the Identified Vulnerabilities

The vulnerabilities, designated as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, were addressed in a security advisory, VMSA-2026-0004, issued on June 8, 2026. Each of these vulnerabilities has received a CVSSv3 base score of 8.0, categorizing them as “Important” in terms of severity. As there are no available workarounds, applying patches is the only recommended solution.

Understanding Stored XSS Risks

The advisory reveals that the issues stem from improperly sanitized user inputs within VMware Cloud Foundation Operations, leading to multiple stored XSS vulnerabilities. Unlike reflected XSS, stored XSS poses a higher risk as the malicious code remains on the server and can execute whenever a user accesses the compromised component, potentially affecting numerous users.

Attackers with privileges to create policies, views, or text-widgets can embed malicious scripts into these elements. When these scripts are displayed in the management interface, they execute as if by other users, including administrators with higher privileges, allowing the attacker to perform unauthorized actions.

Mitigation and Security Measures

Though successful exploitation requires authenticated access with specific rights, the potential for privilege escalation within a virtualization management platform underscores the critical nature of these vulnerabilities. These issues were reported to Broadcom by Alexis Bernazzani of Visa Inc., with the advisory covering a wide range of affected Broadcom products.

Broadcom has released necessary patches and updates that should be applied promptly as outlined in the Response Matrix. The advisory includes a comprehensive list of vulnerable and fixed product versions.

Administrators are urged to prioritize installing these patches immediately, given the lack of alternative mitigations. Additionally, reviewing and tightening role assignments and permissions for creating policies, views, and text-widgets can help reduce the risk of exploitation until the patches are fully deployed.

By staying informed and taking swift action, organizations can better safeguard their infrastructure against these significant threats.

Cyber Security News Tags:admin security, Broadcom, cloud security, CVE, CVSS score, Cybersecurity, IT security, patch management, security advisory, security patch, Virtualization, VMware, vulnerability management, XSS vulnerabilities

Post navigation

Previous Post: OpenAI Expands ChatGPT Security Features Globally
Next Post: Legacy WebBrowser Control Exploits Lead to RCE

Related Posts

Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems Cyber Security News
Microsoft Defender Identifies New Trojanized Gaming Tool Threat Microsoft Defender Identifies New Trojanized Gaming Tool Threat Cyber Security News
Silver Fox Exploits Fake Tax Emails for Malware Attack Silver Fox Exploits Fake Tax Emails for Malware Attack Cyber Security News
SysUpdate Malware Variant Targets Linux with Encrypted C2 SysUpdate Malware Variant Targets Linux with Encrypted C2 Cyber Security News
Critical HPE Telco Service Activator Security Flaw Exposed Critical HPE Telco Service Activator Security Flaw Exposed Cyber Security News
Proxyware Malware Disguised as Notepad++ Tool Leverages Windows Explorer Process to Hijack Systems Proxyware Malware Disguised as Notepad++ Tool Leverages Windows Explorer Process to Hijack Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • A Security Secures $37M for Advanced Cyber Defense
  • Critical Linux Kernel Flaw Allows Root Privilege Escalation
  • Security Concerns Rise with AI-Driven Vibe Coding
  • The Emerging Threat of Mythos in Open Source
  • UNC3753 Targets US Law Firms with Vishing Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • A Security Secures $37M for Advanced Cyber Defense
  • Critical Linux Kernel Flaw Allows Root Privilege Escalation
  • Security Concerns Rise with AI-Driven Vibe Coding
  • The Emerging Threat of Mythos in Open Source
  • UNC3753 Targets US Law Firms with Vishing Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark