[VMware Critical Advisory] VMSA-2026-0006 – ESX, vCenter, Workstation & Fusion Vulnerabilities

Date: 29 July 2026
Advisory: VMSA-2026-0006
Severity: Critical (CVSS 2.7–9.8)
Affected Products: ESX, vCenter, Workstation, Fusion, Cloud Foundation, vSphere Foundation, Telco Cloud Platform, Telco Cloud Infrastructure
Workaround: None
Fix Available: Yes

Broadcom has published VMSA-2026-0006, addressing five vulnerabilities across core VMware datacenter and desktop products:

  • CVE-2026-59309 – vCenter authentication bypass (Directory Service)
    → Affects: vCenter (standalone), Cloud Foundation, vSphere Foundation
    → Remote authentication bypass in VMware Directory Service
    → CVSS: 9.8 (remote, unauthenticated, full compromise)
  • CVE-2026-59310 – vCenter directory traversal (Syslog server)
    → Affects: vCenter (standalone), Cloud Foundation, vSphere Foundation
    → Directory traversal in embedded Syslog server, arbitrary code execution
    → CVSS: 9.8
  • CVE-2026-47876 – ESX VMXNET3 OOB write / VM escape
    → Affects: ESX, Cloud Foundation, vSphere Foundation, Telco Cloud
    → Out‑of‑bounds write via VMXNET3 virtual NIC – potential host‑level code execution from guest
    → CVSS: 9.3
  • CVE-2026-41703 – ESX / Workstation / Fusion OOB read
    → Affects: ESX, Workstation, Fusion, Cloud Foundation, Telco Cloud
    → Out‑of‑bounds read leading to info leak or DoS of host process
    → CVSS: 7.6 (server) / 2.7 (desktop)
  • CVE-2026-41709 – ESX insufficient logging
    → Affects: ESX, Cloud Foundation, Telco Cloud
    → Certain administrative operations may not be logged
    → CVSS: 2.7

Key Insights

  • vCenter is the highest‑risk component. Both CVE-2026-59309 and CVE-2026-59310 are remotely exploitable with no authentication, giving an attacker a direct path to vCenter compromise if it is reachable on the network.
  • ESX VMXNET3 issue is a classic VM escape. CVE-2026-47876 allows a local admin in a VM using VMXNET3 to execute code on the ESX host; environments with VMXNET3 widely deployed should treat this as a priority patch item. Guest NICs using other virtual adapters are not impacted, but host patching is still the only robust fix.
  • Server vs desktop impact differs. On ESX, the OOB read (CVE-2026-41703) can cause info disclosure or DoS of host processes; on Workstation/Fusion the impact is limited to information disclosure on the local hypervisor.
  • Logging weakness is low severity but operationally relevant. CVE-2026-41709 does not directly enable compromise, but it can degrade auditability and forensic capabilities if a malicious admin abuses it.
  • No workarounds. There are no supported mitigations; upgrading to fixed builds is mandatory. Async paths are provided for Cloud Foundation and Telco Cloud via KB88287 and dedicated Telco KBs.

Recommended Action

1. Patch vCenter first (remote, unauthenticated)

Prioritize all vCenter instances – standalone and those embedded in Cloud Foundation / vSphere Foundation:

  • vCenter 9.1.x: update to 9.1.0.0300
  • vCenter 9.0.x: update to 9.0.2.0100
  • vCenter 8.0: update to 8.0 U3k
  • Cloud Foundation 5.x: apply async patch to vCenter 8.0 U3k (per KB88287)

For Telco Cloud Platform / Telco Cloud Infrastructure, follow the vCenter guidance in KB449886.

Ensure that internet‑exposed or broadly reachable vCenter instances are patched as soon as possible and review network exposure (firewalls, VPN, bastion access) as part of the change.

2. Patch ESX for VMXNET3 VM escape

For CVE-2026-47876:

  • ESX 9.1.x.x (Cloud Foundation / vSphere Foundation): ESXi-9.1.0.0200-25557999
  • ESX 9.0.x.x (Cloud Foundation / vSphere Foundation): ESXi-9.0.2.0100-25595025
  • ESX 8.0: ESXi80U3k-25595708
  • Cloud Foundation 5.x: follow async ESX patching via KB88287
  • Telco Cloud Platform / Telco Cloud Infrastructure: patch according to KB449886

As a risk‑reduction measure during your patch window, you can identify VMs using VMXNET3 and treat them as high‑risk tenants (network isolation, stricter access), but this does not replace host patching.

3. Address ESX / Workstation / Fusion OOB read

For CVE-2026-41703:

  • ESX 9.1.x.x: included in ESXi-9.1.0.0-25370933
  • ESX 9.0.x.x: ESXi-9.0.2.0100-25595025
  • ESX 8.0: ESXi80U3i-25205845
  • Cloud Foundation 5.x: 5.2.3
  • Workstation: update to 26H1
  • Fusion: update to 26H1

4. Fix ESX logging weakness

For CVE-2026-41709:

  • ESX 9.1.x.x: ESXi-9.1.0.0-25370933
  • ESX 9.0.x.x: ESXi-9.0.2.0100-25595025
  • ESX 8.0: ESXi80U3j-25429389
  • Cloud Foundation 5.x: 5.2.4
  • Telco Cloud Platform / Telco Cloud Infrastructure: per KB449886

Leave a Reply