VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)
38017
29 July 2026
29 July 2026
OPEN
CRITICAL
2.7-9.8
None
CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709
| Advisory ID: | VMSA-2026-0006 |
| Advisory Severity: | Critical |
| CVSSv3 Range: | 2.7-9.8 |
| Synopsis: | VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) |
| Issue date: | 2026-07-29 |
| Updated on: | 2026-07-29 (Initial Advisory) |
| CVE(s) |
CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709 |
1. Impacted Products
- VMware ESX
- VMware vCenter
- VMware Workstation
- VMware Fusion
- VMware Cloud Foundation
- VMware vSphere Foundation
- VMware Telco Cloud Platform
- VMware Telco Cloud Infrastructure
2. Introduction
Multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products.
3a. vCenter authentication-bypass vulnerability (CVE-2026-59309)
Description:
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Known Attack Vectors:
A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Resolution:
To remediate CVE-2026-59309 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds:
None
Additional Documentation:
A supplemental FAQ was created for clarification. Please see: https://brcm.tech/vmsa-2026-0006
Acknowledgments:
Broadcom would like to thank Phil Brass and Matt South of Atredis Partners for reporting this issue to us.
Notes:
[1] Please note that patches are cumulative, meaning the current version includes all previously released fixes. While CVE-2026-59309 was addressed in 9.1.0.0200 first, version 9.1.0.0300 is the most recent version currently available which includes the fix for this CVE.
3b. vCenter directory-traversal vulnerability (CVE-2026-59310)
Description:
VMware vCenter contains a directory traversal vulnerability in the Syslog server. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Known Attack Vectors:
A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Resolution:
To remediate CVE-2026-59310 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds:
None
Additional Documentation:
A supplemental FAQ was created for clarification. Please see: https://brcm.tech/vmsa-2026-0006
Acknowledgments:
Broadcom would like to thank Phil Brass and Matt South of Atredis Partners for reporting this issue to us.
Notes:
None.
Response Matrix 3a and 3b:
|
VMware Product |
Component |
Version |
Running On |
CVE |
CVSSv3 |
Severity |
Fixed Version |
Workarounds |
Additional Documentation |
|---|---|---|---|---|---|---|---|---|---|
|
VMware Cloud Foundation, VMware vSphere Foundation |
vCenter | 9.1.x.x | Any | CVE-2026-59309, CVE-2026-59310 | 9.8 | Critical |
[1] 9.1.0.0300 |
None | FAQ |
|
VMware Cloud Foundation, VMware vSphere Foundation |
vCenter | 9.0.x.x | Any | CVE-2026-59309, CVE-2026-59310 | 9.8 | Critical | 9.0.2.0100 | None | FAQ |
| VMware vCenter | N/A | 8.0 | Any | CVE-2026-59309, CVE-2026-59310 | 9.8 | Critical | 8.0 U3k | None | |
| VMware Cloud Foundation | vCenter | 5.x | Any |
CVE-2026-59309, CVE-2026-59310 |
9.8 | Critical | Async patch to 8.0 U3k | None | Async Patching Guide: KB88287 |
| VMware Telco Cloud Platform | vCenter | 3.0, 4.x, 5.0.x, 5.1.x | Any |
CVE-2026-59309, CVE-2026-59310 |
9.8 | Critical | KB449886 |
None | None |
| VMware Telco Cloud Infrastructure | vCenter | 3.0 | Any |
CVE-2026-59309, CVE-2026-59310 |
9.8 | Critical | KB449886 | None | None |
[1] Please note that patches are cumulative, meaning the current version includes all previously released fixes. While CVE-2026-59309 was addressed in 9.1.0.0200 first, version 9.1.0.0300 is the most recent version currently available which includes the fix for this CVE.
3c. VMXNET3 out-of-bounds write vulnerability (CVE-2026-47876)
Description:
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3.
Known Attack Vectors:
A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
Resolution:
To remediate CVE-2026-47876 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds:
None
Additional Documentation:
A supplemental FAQ was created for clarification. Please see: https://brcm.tech/vmsa-2026-0006
Acknowledgments:
Broadcom would like to thank Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG working with the Pwn2Own held by Zero day initiative for reporting this issue to us.
Notes:
None.
Response Matrix:
|
VMware Product |
Component |
Version |
Running On |
CVE |
CVSSv3 |
Severity |
Fixed Version |
Workarounds |
Additional Documentation |
|---|---|---|---|---|---|---|---|---|---|
|
VMware Cloud Foundation, VMware vSphere Foundation |
ESX | 9.1.x.x | Any | CVE-2026-47876 | 9.3 | Critical | ESXi-9.1.0.0200-25557999 | None | FAQ |
|
VMware Cloud Foundation, VMware vSphere Foundation |
ESX | 9.0.x.x | Any | CVE-2026-47876 | 9.3 | Critical | ESXi-9.0.2.0100-25595025 | None | FAQ |
| VMware ESX | N/A | 8.0 | Any | CVE-2026-47876 | 9.3 | Critical | ESXi80U3k-25595708 | None | |
| VMware Cloud Foundation | ESX | 5.x | Any |
CVE-2026-47876 |
9.3 | Critical | Async Patching Guide: KB88287 | None | FAQ |
| VMware Telco Cloud Platform | ESX | 5.0.x, 5.1.x | Any |
CVE-2026-47876 |
9.3 | Critical | KB449886 | None | None |
3d. Out-of-bounds read vulnerability (CVE-2026-41703)
Description:
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. Broadcom has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.6.
Known Attack Vectors:
A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
Resolution:
To remediate CVE-2026-41703 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds:
None
Additional Documentation:
None.
Acknowledgments:
Broadcom would like to thank Maxim Suhanov (@errno_fail) for reporting this issue to us.
Notes:
None.
Response Matrix:
|
VMware Product |
Component |
Version |
Running On |
CVE |
CVSSv3 |
Severity |
Fixed Version |
Workarounds |
Additional Documentation |
|---|---|---|---|---|---|---|---|---|---|
|
VMware Cloud Foundation, VMware vSphere Foundation |
ESX | 9.1.x.x | Any | CVE-2026-41703 | 7.6 | Important | ESXi-9.1.0.0-25370933 | None | None |
|
VMware Cloud Foundation, VMware vSphere Foundation |
ESX | 9.0.x.x | Any | CVE-2026-41703 | 7.6 | Important | ESXi-9.0.2.0100-25595025 | None | None |
| VMware ESX | N/A | 8.0 | Any | CVE-2026-41703 | 7.6 | Important | ESXi80U3i-25205845 | None |
None |
| VMware Workstation | N/A | 25H2 | Any |
CVE-2026-41703 |
2.7 | Low | 26H1 | None | None |
| VMware Fusion | N/A | 25H2 | Any |
CVE-2026-41703 |
2.7 | Low | 26H1 | None | None |
| VMware Cloud Foundation | ESX | 5.x | Any |
CVE-2026-41703 |
7.6 | Important | 5.2.3 | None | Async Patching Guide: KB88287 |
| VMware Telco Cloud Platform | ESX | 5.0.x, 5.1.x | Any |
CVE-2026-41703 |
7.6 | Important | KB449886 | None | None |
3e. ESX insufficient logging vulnerability (CVE-2026-41709)
Description:
VMware ESX contains an insufficient logging vulnerability. Broadcom has evaluated the severity of this issue to be in the Low severity range with a maximum CVSSv3 base score of 2.7.
Known Attack Vectors:
A malicious administrator could exploit this issue to perform certain operations without them being logged.
Resolution:
To remediate CVE-2026-41709 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds:
None.
Additional Documentation:
None.
Acknowledgments:
Broadcom would like to thank Ian Barton of CrowdStrike for reporting this issue to us.
Notes:
None.
Response Matrix:
|
VMware Product |
Component |
Version |
Running On |
CVE |
CVSSv3 |
Severity |
Fixed Version |
Workarounds |
Additional Documentation |
|---|---|---|---|---|---|---|---|---|---|
|
VMware Cloud Foundation, VMware vSphere Foundation |
ESX | 9.1.x.x | Any | CVE-2026-41709 | 2.7 | Low | ESXi-9.1.0.0-25370933 | None | None |
|
VMware Cloud Foundation, VMware vSphere Foundation |
ESX | 9.0.x.x | Any | CVE-2026-41709 | 2.7 | Low | ESXi-9.0.2.0100-25595025 | None | None |
| VMware ESX | N/A | 8.0 | Any | CVE-2026-41709 | 2.7 | Low | ESXi80U3j-25429389 | None |
None |
| VMware Cloud Foundation | ESX | 5.x | Any |
CVE-2026-41709 |
2.7 | Low | 5.2.4 | None | Async Patching Guide: KB88287 |
| VMware Telco Cloud Platform | ESX | 5.0.x, 5.1.x | Any |
CVE-2026-41709 |
2.7 | Low | KB449886 | None | None |
4. References
VMware Cloud Foundation 9.1.0.x
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20Cloud%20Foundation&displayGroup=VMware%20Cloud%20Foundation%209&release=9.1.0.0&os=&servicePk=540528&language=EN
https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/patch-releases-9-1-0-x.html
VMware Cloud Foundation 9.0.x
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20Cloud%20Foundation&displayGroup=VMware%20Cloud%20Foundation%209&release=9.0.2.0&os=&servicePk=537791&language=EN
https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-0/release-notes/patch-releases-9-0-0-x.html
VMware vSphere Foundation 9.1.0.x
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20vSphere%20Foundation&displayGroup=VMware%20vSphere%20Foundation%209&release=9.1.0.0&os=&servicePk=542815&language=EN
VMware vSphere Foundation 9.0.x
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20vSphere%20Foundation&displayGroup=VMware%20vSphere%20Foundation%209&release=9.0.2.0&os=&servicePk=537838&language=EN
VMware Cloud Foundation 5.2.4
Downloads and Documentation:
https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-5-2-and-earlier/5-2/vcf-release-notes/vmware-cloud-foundation-524-release-notes.html
VMware Cloud Foundation 5.2.3
Downloads and Documentation:
https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-5-2-and-earlier/5-2/vcf-release-notes/vmware-cloud-foundation-523-release-notes.html
VMware vCenter 9.1.0.0300
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?displayGroup=VMware%20Cloud%20Foundation%209&release=9.1.0.0&os=&servicePk=540528&language=EN&groupId=540509&viewGroup=true
https://techdocs.broadcom.com/bin/gethidpage?ux-context-string=vcenter-9-1-0-3&appid=vcf-9-1&language=en&format=rendered
VMware vCenter 9.0.2.0100
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?displayGroup=VMware%20Cloud%20Foundation%209&release=9.0.2.0&os=&servicePk=537791&language=EN&groupId=537830&viewGroup=true
https://techdocs.broadcom.com/bin/gethidpage?ux-context-string=9-0-2-0-1&appid=vcf-9-0&language=en&format=rendered
VMware ESX 9.1.0.0200
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?displayGroup=VMware%20Cloud%20Foundation%209&release=9.1.0.0&os=&servicePk=540528&language=EN&groupId=540591&viewGroup=true
https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/patch-releases-9-1-0-x/vsphere/esx/esx-9-1-0-0200-release-notes.html
VMware ESX 9.0.2.0100
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?displayGroup=VMware%20Cloud%20Foundation%209&release=9.0.2.0&os=&servicePk=537791&language=EN&groupId=537810&viewGroup=true
https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-0/release-notes/patch-releases-9-0-0-x/vsphere/esx/esx-9-0-2-0100-release-notes.html
VMware vCenter 8.0 U3k
Downloads and Documentation:
https://support.broadcom.com/web/ecx/solutiondetails?patchId=16109
https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/vcenter-server-update-and-patch-release-notes/vsphere-vcenter-server-80u3k-release-notes.html
VMware ESX 8.0 U3k
Downloads and Documentation:
https://support.broadcom.com/web/ecx/solutiondetails?patchId=16106
https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u3k-release-notes.html
VMware ESX 8.0 U3j
Downloads and Documentation:
https://support.broadcom.com/web/ecx/solutiondetails?patchId=16046
https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u3j-release-notes.html
VMware ESX 8.0 U3i
Downloads and Documentation:
https://support.broadcom.com/web/ecx/solutiondetails?patchId=16046
https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u3i-release-notes.html
VMware Workstation 26H1
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productdownloads?subfamily=VMware%20Workstation%20Pro&freeDownloads=true
https://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/workstation-pro/26H1.html
VMware Fusion 26H1
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20Fusion&displayGroup=VMware%20Fusion%2026H1&release=26H1&os=&servicePk=543219&language=EN&freeDownloads=true
https://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/fusion-pro/26H1.html
Mitre CVE Dictionary Links:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59309
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59310
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47876
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41703
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41709
FIRST CVSSv3 Calculator:
CVE-2026-59309: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-59310: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-47876: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-41703: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
CVE-2026-41709: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
5. Change Log:
2026-07-29 VMSA-2026-0006
Initial security advisory.
6. Contact:
E-mail: [email protected]
PGP key
https://knowledge.broadcom.com/external/article/321551
VMware Security Advisories
https://www.broadcom.com/support/vmware-security-advisories
VMware External Vulnerability Response and Remediation Policy
https://www.broadcom.com/support/vmware-services/security-response
VMware Lifecycle Support Phases
https://support.broadcom.com/group/ecx/productlifecycle
VMware Security Blog
https://blogs.vmware.com/security
X
https://x.com/VMwareSRC
Copyright 2026 Broadcom. All rights reserved.