VMware patches multiple critical products vulnerabilities
CERT-FR advisory details multiple vulnerabilities in VMware Cloud Foundation, ESXi, vCenter, Workstation and Fusion enabling RCE, DoS and data exposure.
CERT-FR has issued an advisory covering multiple vulnerabilities affecting a broad range of VMware (Broadcom) products, including Cloud Foundation, ESXi, vCenter, vSphere Foundation, Telco Cloud Infrastructure/Platform, Workstation and Fusion. The flaws allow remote code execution, remote denial of service, security policy bypass, and breach of data confidentiality, depending on the specific product and version. Five CVEs are referenced (CVE-2026-41703, CVE-2026-41709, CVE-2026-47876, CVE-2026-59309, CVE-2026-59310), tied to Broadcom security bulletin 38017 published July 29, 2026.
Affected versions span a wide swath of VMware's enterprise virtualization stack, including unpatched Cloud Foundation 5.x and 9.x builds, ESXi 8.0 prior to a specific build, vCenter 8.0 prior to U3k, and Telco Cloud products lacking specific KB patches. No evidence of active exploitation is mentioned in the advisory; organizations are directed to apply vendor-supplied patches referenced in the Broadcom bulletin. Given the widespread use of VMware virtualization infrastructure in enterprise and cloud environments, unpatched systems present a meaningful risk surface for remote code execution and confidentiality breaches.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0949
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free