This article provides upgrade guidance for environments applying (8.0 U3k) patch to address VMSA-2026-0006.1 vulnerability while planning future migrations to VMware vSphere Foundation (VVF) 9.1.x. or VMware Cloud Foundation 9.1.x
VMware vCenter Server 8.0 U3g
VMware vCenter Server 8.0 U3k
VMware ESXi 8.0 U3g
VMware vSphere Foundation (VVF) 9.1.0
Security releases often contain updated code branches that can replace the code in major baseline releases. Upgrading a component to a newer patch release (like 8.0 U3k) can create a scenario where upgrading to an existing major release (like 9.1.0) is classified as an unsupported "back-in-time" upgrade.
Upgrading vCenter Server to 8.0 U3k will temporarily block the upgrade path to VVF 9.1.0. If the U3k patch is applied, the environment must remain on the 8.0 U3k branch until a future VVF 9.1.x release is published that officially restores the forward upgrade path from 8.0 U3k.
From a standard VMware interoperability perspective, there are no compatibility issues between vCenter Server 8.0 U3k and ESXi 8.0 U3g. It is fully supported to manage an older ESXi 8.0 update version with a patched vCenter 8.0 instance. Check Interoperability Matrix
However, leaving ESXi hosts on 8.0 U3g leaves the infrastructure vulnerable to critical exploits such as CVE-2026-47876, an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. Without applying the corresponding ESXi 8.0 U3k patch, an attacker with local administrative privileges inside a virtual machine could potentially execute code directly on the underlying ESXi host. It is strongly advised to apply the 8.0 U3k patch to both vCenter Server and ESXi to fully secure the environment unless there's an active planned migration to VVF 9.1.X./VCF 9.1.x
Once Broadcom publishes a future VVF 9.1.x/VCF 9.1.x release that explicitly supports upgrading from 8.0 U3k, standard VVF 9.1/VCF 9.1 upgrade plans can resume.