# VMware patches multiple critical products vulnerabilities

Published: 2026-07-30 · Severity: high · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/e6eb579b-633d-540f-a19c-4f1b5750007d/vmware-patches-multiple-critical-products-vulnerabilities

> CERT-FR advisory details multiple vulnerabilities in VMware Cloud Foundation, ESXi, vCenter, Workstation and Fusion enabling RCE, DoS and data exposure.

CERT-FR has issued an advisory covering multiple vulnerabilities affecting a broad range of VMware (Broadcom) products, including Cloud Foundation, ESXi, vCenter, vSphere Foundation, Telco Cloud Infrastructure/Platform, Workstation and Fusion. The flaws allow remote code execution, remote denial of service, security policy bypass, and breach of data confidentiality, depending on the specific product and version. Five CVEs are referenced (CVE-2026-41703, CVE-2026-41709, CVE-2026-47876, CVE-2026-59309, CVE-2026-59310), tied to Broadcom security bulletin 38017 published July 29, 2026.

Affected versions span a wide swath of VMware's enterprise virtualization stack, including unpatched Cloud Foundation 5.x and 9.x builds, ESXi 8.0 prior to a specific build, vCenter 8.0 prior to U3k, and Telco Cloud products lacking specific KB patches. No evidence of active exploitation is mentioned in the advisory; organizations are directed to apply vendor-supplied patches referenced in the Broadcom bulletin. Given the widespread use of VMware virtualization infrastructure in enterprise and cloud environments, unpatched systems present a meaningful risk surface for remote code execution and confidentiality breaches.

## Mentioned in this report

- Vulnerabilities: CVE-2026-41703, CVE-2026-41709, CVE-2026-47876, CVE-2026-59309, CVE-2026-59310

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0949

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e6eb579b-633d-540f-a19c-4f1b5750007d/vmware-patches-multiple-critical-products-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
