A denial‑of‑service (DoS) vulnerability, registered as CVE‑2026‑49975, has been identified in the HTTP/2 protocol in VMware Cloud Foundation (VCF).
This security concern can allow an attacker to exploit the HTTP/2 implementation to disrupt services and cause unexpected application downtime.
This article clarifies whether VMware NSX is affected by CVE‑2026‑49975.
VMware NSX
VMware NSX is not affected by CVE-2026-49975.
Broadcom is aware of CVE-2026-49975.
Refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information or support, Contact Broadcom Support