VMware response to VMSA-2026-0006 (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)
search cancel

VMware response to VMSA-2026-0006 (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)

book

Article ID: 449886

calendar_today

Updated On:

Products

VMware Telco Cloud Infrastructure VMware Telco Cloud Platform

Issue/Introduction

Steps to remediate VMSA-2026-0006 on VMware Telco Cloud products.

Environment

  • VMware Cloud Foundation ESX 9.1.x.x (Builds prior to 25370933)
  • VMware vSphere Foundation ESX 9.1.x.x (Builds prior to 25370933)
  • VMware Cloud Foundation ESX 9.0.x.x (Builds prior to 25595025)
  • VMware vSphere Foundation ESX 9.0.x.x (Builds prior to 25595025)
  • VMware ESXi 8.0 (Builds prior to 25205845)
  • VMware Workstation 25H2 (Builds prior to 26H1)
  • VMware Fusion 25H2 (Builds prior to 26H1)
  • VMware Cloud Foundation ESX 5.x (VCF versions prior to 5.2.3)
  • VMware Telco Cloud Platform ESX 3.0, 4.x, 5.0.x, 5.1.x
  • VMware Telco Cloud Infrastructure 3.0

Resolution

vCenter authentication-bypass vulnerability (CVE-2026-59309)
vCenter directory-traversal vulnerability (CVE-2026-59310):

VMware ProductComponentVersionFixed VersionLink
VMware Cloud Foundation,
VMware vSphere Foundation
vCenter9.1.x.x9.1.0.0300vCenter 9.1.0.0300
VMware Cloud Foundation,
VMware vSphere Foundation
vCenter9.0.x.x
9.0.2.0100
vCenter 9.0.2.0100
VMware vCenterN/A8.08.0 U3kvCenter 8.0 U3k
VMware vCenterN/A8.08.0 U2fvCenter 8.0 U2f
VMware Cloud FoundationvCenter5.xAsync patch to 8.0 U3kAsync Patching Guide: KB88287
VMware Telco Cloud PlatformvCenterTCI: 3.0
TCP: 3.0, 4.x, 5.0.x, 5.1.x
8.0 U3kvCenter 8.0 U3k

 

VMXNET3 out-of-bounds write vulnerability (CVE-2026-47876):

VMware ProductComponentVersionFixed VersionLink
VMware Cloud Foundation,
VMware vSphere Foundation
ESX9.1.x.x9.1.0.0200ESXi-9.1.0.0200
VMware Cloud Foundation,
VMware vSphere Foundation
ESX9.0.x.x9.0.2.0100ESXi-9.0.2.0100
VMware ESXiN/A8.08.0 U3kESXi 8.0 U3k
VMware ESXiN/A8.08.0 U2fESXi 8.0 U2f
VMware Cloud FoundationESXi5.xAsync patch to 8.0 U3k Async Patching Guide: KB88287
VMware Telco Cloud PlatformESXiTCI: None
TCP: 5.0.x, 5.1.x
8.0 U3kvCenter 8.0 U3k

 

Out-of-bounds read vulnerability (CVE-2026-41703):

VMware ProductComponentVersionFixed VersionLink
VMware Cloud Foundation,
VMware vSphere Foundation
ESX9.1.x.x9.1.0.0200ESXi-9.1.0.0
VMware Cloud Foundation,
VMware vSphere Foundation
ESX9.0.x.x9.0.2.0100ESXi-9.0.2.0100
VMware ESXiN/A8.08.0 U3iESXi 8.0 U3i
VMware WorkstationN/A25H226H1Workstation 26H1
VMware FusionN/A25H226h1Fusion 26H1
VMware Cloud FoundationESXi5.x5.2.3 Async Patching Guide: KB88287
VMware Telco Cloud PlatformESXiTCI: None
TCP: 5.0.x, 5.1.x
8.0 U3iESXi 8.0 U3i

 

ESX insufficient logging vulnerability (CVE-2026-41709) 

VMware ProductComponentVersionFixed VersionLink
VMware Cloud Foundation,
VMware vSphere Foundation
ESX9.1.x.x9.1.0.0200ESXi-9.1.0.0
VMware Cloud Foundation,
VMware vSphere Foundation
ESX9.0.x.x9.0.2.0100ESXi-9.0.2.0100
VMware ESXiN/A8.08.0 U3jESXi 8.0 U3j
VMware Cloud FoundationESXi5.x5.2.4 Async Patching Guide: KB88287
VMware Telco Cloud PlatformESXiTCI: None
TCP: 5.0.x, 5.1.x
8.0 U3jESXi 8.0 U3j

 

Note: For unlisted TCP/TCI versions or versions under extended support, please contact VMware support for upgrade, mitigation, and migration guidance.