In VCF Automation 9.0.x, security scanners may flag the following CVEs that are associated with OpenSSH:
CVE-2026-35414
CVE-2026-35385
CVE-2026-35386
CVE-2026-35387
CVE-2026-35388
Product: VCF Automation
Version: 9.0.x
VMware by Broadcom is aware of CVE-2026-35414, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, and CVE-2026-35388.
Please refer to the release notes for existing and forthcoming product releases for any updates in relation to these CVEs.
Should you require further information please contact Broadcom Support: https://support.broadcom.com