VMware Product Security Update Advisory

VMware Product Security Update Advisory

VMware Product Security Update Advisory.


VMware has released security updates that address several vulnerabilities discovered in ESX, vCenter, Workstation, Fusion, Telco Cloud Platform, and Telco Cloud Infrastructure.

Addressed Vulnerabilities.

  • CVE-2026-41703: An out-of-bounds read vulnerability affecting VMware ESX, Workstation, and Fusion.
  • CVE-2026-41709: An insufficient logging vulnerability affecting VMware ESX.
  • CVE-2026-47876: An out-of-bounds write vulnerability in VMXNET3 (virtual network adapter) in VMware ESX.
  • CVE-2026-59309: A vulnerability that allows authentication bypass in VMware Directory Service within VMware vCenter.
  • CVE-2026-59310: A directory traversal vulnerability in the Syslog server (log collection server) of VMware vCenter.

Affected Products.

The affected products are VMware Cloud Foundation, VMware vSphere Foundation, VMware ESX 8.0, VMware Workstation 25H2, VMware Fusion 25H2, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.

Recommended Actions.

Vulnerability Patches have been released in the latest updates. Users of the affected products should update to the latest version of the Patch as instructed.

Key Patch Examples.

  • CVE-2026-41703: Update VMware ESX 8.0 To ESXi80U3i-25205845, and update VMware Workstation and VMware Fusion to 26H1.
  • CVE-2026-41709: Update VMware ESX 8.0 To ESXi80U3j-25429389.
  • CVE-2026-47876: Update VMware ESX 8.0 To VMware ESXi80U3k-25595708.
  • CVE-2026-59309, CVE-2026-59310: Update VMware vCenter 8.0 To 8.0 U3k.

For certain VMware Cloud Foundation and VMware Telco Cloud Platform products, apply patches or asynchronous patches as instructed on the reference site.