LIVE · cybersecurity feed
Live wire
vendor

Broadcom

21 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical2
High19
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-478659.8criticalvmware avi load balancerVMware Avi Load Balancer contains an authentication bypass vulnerability.50d ago
CVE-2026-227529.6criticalspring authorization serverAuthentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.52d ago
CVE-2026-478718.8highvmware avi load balancerVMware Avi Load Balancer contains a directory traversal vulnerability.50d ago
CVE-2026-572158.8highrabbitmq serverRabbitMQ is a messaging and streaming broker.57d ago
CVE-2026-478698.7highvmware avi load balancerVMware Avi Load Balancer contains a remote code execution vulnerability.50d ago
CVE-2026-478678.7highvmware avi load balancerVMware Avi Load Balancer contains a remote code execution vulnerability.50d ago
CVE-2026-409998.6highspring web servicesWhen WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connec87d ago
CVE-2026-478668.3highvmware avi load balancerVMware Avi Load Balancer contains an authorization bypass vulnerability.50d ago
CVE-2026-409988.2highspring web servicesJaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parse87d ago
CVE-2026-593168.2highspring authorization serverSpring Authorization Server's default consent page renders user-controlled values without HTML entity encoding.9d ago
CVE-2026-409948.2highspring web servicesWss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validat87d ago
CVE-2026-448388.1highrabbitmq serverRabbitMQ is a messaging and streaming broker.101d ago
CVE-2026-478687.8highvmware avi load balancerVMware Avi Load Balancer contains a local privilege escalation vulnerability.50d ago
CVE-2026-572127.7highrabbitmq serverRabbitMQ is a messaging and streaming broker.57d ago
CVE-2026-592847.6highspring cloud commonsThere is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled.9d ago
CVE-2026-417167.5highspring data commonsSpring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache ke88d ago
CVE-2026-416957.5highspring data commonsSpring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-88d ago
CVE-2026-572197.5highrabbitmq serverRabbitMQ is a messaging and streaming broker.57d ago
CVE-2026-417087.5highspring cloud sleuthIn Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-se82d ago
CVE-2026-572207.5highrabbitmq serverRabbitMQ is a messaging and streaming broker.57d ago
CVE-2026-478707.1highvmware avi load balancerVMware Avi Load Balancer contains a privilege escalation vulnerability.50d ago

Filter the full tracker by Broadcom

Our coverage of Broadcom

vulnerabilitycritical

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

CVE-2026-33824

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchan