Error: OpenSSH vulnerabilities (CVE-2026-35386, CVE-2026-35385, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414) in VMware vSphere.
search cancel

Error: OpenSSH vulnerabilities (CVE-2026-35386, CVE-2026-35385, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414) in VMware vSphere.

book

Article ID: 439026

calendar_today

Updated On:

Products

VMware vCenter Server VMware SDDC Manager / VCF Installer

Issue/Introduction

Vulnerability scanners identified multiple OpenSSH CVEs within VMware environments using "banner grabbing" techniques. These scans match the OpenSSH version string against known vulnerabilities but may not account for Broadcom's backported security patches.

Symptoms

Security scans flag CVE-2026-35386, CVE-2026-35385, CVE-2026-35387, CVE-2026-35388, and CVE-2026-35414.
Scanning tools report OpenSSH version < 10.3 on ESXi or < 9.8 on vCenter.

Environment

  • VMware vSphere 8.0.3 (ESXi and vCenter Server)
  • VMware Cloud Foundation (VCF) 5.x / 9.x
  • VMware Live Site Recovery 9.x
  • VMware Live Recovery 9.x
  • Site Recovery Manager 8.x

Cause

The identified CVEs impact OpenSSH versions earlier than 10.3. In VMware appliances and ESXi, OpenSSH is a bundled component. Broadcom utilizes a backporting model where security fixes are integrated into existing version branches rather than incrementing the major version number.

Resolution

Broadcom Engineering is aware of these vulnerabilities.

  1. Maintain SSH Status: Ensure the ESXi SSH service is disabled in production environments unless required for active troubleshooting.
  2. For defects and enhancements: Subscribe to this article (Reference: Subscribe to a Broadcom knowledge article by article or product ) to receive updates on fix status.
  3. Monitor for Updates: Fixes are targeted for upcoming releases of vSphere 8.0 and VCF.

Additional Information

To speak with a customer representative or a Support Engineer see . Scroll to the bottom of the page and click on your respective region.