A denial-of-service (DoS) vulnerability, registered as CVE-2026-49975, has been identified in the HTTP/2 protocol in VCF Operations, VCF Automation and VCF Operations for Logs.
This security concern can allow an attacker to exploit the HTTP/2 implementation to disrupt services and cause unexpected application downtime.
Environment
VCF Operations 9.0.1
VCF Operations for Logs 9.0.1
VCF Automation 9.0.1
Resolution
VMware By Broadcom is aware of CVE-2026-49975. Refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE. Should you require further information or support, Contact Broadcom Support