cbcvebase.
CVE-2026-47865
published 2026-07-18

CVE-2026-47865: VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by…

PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.87%
55.2th percentile
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

Affected

3 ranges
VendorProductVersion rangeFixed in
vmwareavi_load_balancer22.1.1 – 22.1.7
vmwareavi_load_balancer30.1.1 – 30.2.6
vmwareavi_load_balancer31.1.1 – 31.2.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.

CVE-2026-47865 — Improper Authentication in Vmware | cvebase