cbcvebase.
CVE-2026-41723
published 2026-06-08

CVE-2026-41723: VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or…

PriorityP340high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
0.40%
32.0th percentile
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

Affected

7 ranges
VendorProductVersion rangeFixed in
vmwarearia_operations>= 8.0 < 8.18.78.18.7
vmwarecloud_foundation
vmwarecloud_foundation>= 5.0 < 8.18.78.18.7
vmwarecloud_foundation>= 9.0 < 9.0.2.09.0.2.0
vmwaretelco_cloud_platform5.0 – 5.1
vmwarevsphere
vmwarevsphere>= 9.0 < 9.0.2.09.0.2.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.