Vulnerability scanners identified multiple OpenSSH CVEs within VMware environments using "banner grabbing" techniques. These scans match the OpenSSH version string against known vulnerabilities but may not account for Broadcom's backported security patches.
Security scans flag CVE-2026-35386, CVE-2026-35385, CVE-2026-35387, CVE-2026-35388, and CVE-2026-35414.
Scanning tools report OpenSSH version < 10.3 on ESXi or < 9.8 on vCenter.
The identified CVEs impact OpenSSH versions earlier than 10.3. In VMware appliances and ESXi, OpenSSH is a bundled component. Broadcom utilizes a backporting model where security fixes are integrated into existing version branches rather than incrementing the major version number.
Broadcom Engineering is aware of these vulnerabilities.
To speak with a customer representative or a Support Engineer see . Scroll to the bottom of the page and click on your respective region.