Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-47867: VMware Avi Load Balancer allows remote code execution

CVE-2026-47867 CVE-2026-47867
Summary

The VMware Avi Load Balancer is vulnerable to a security flaw that could allow an attacker to execute code remotely on the system. This means an attacker could potentially take control of the system. Affected versions should be updated to the latest patch to fix the issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
vmware avi load balancer 32.1.1
Original title
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versio...
Original description
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely.

Affected versions:
32.1.1 (fixed in 32.1.2)
31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)
30.1.1 through 30.2.6 (fixed in 30.2.7)
22.1.1 through 22.1.7 (fixed in 30.2.7)
nvd CVSS3.1 8.7
Vulnerability type
CWE-94 Code Injection
Published: 18 Jul 2026 · Updated: 20 Jul 2026 · First seen: 18 Jul 2026