VMSA-2026-0006.1 Impact on Upgrade Paths and Compatibility - VMware vSphere Foundation and VMware Cloud Foundation
search cancel

VMSA-2026-0006.1 Impact on Upgrade Paths and Compatibility - VMware vSphere Foundation and VMware Cloud Foundation

book

Article ID: 454369

calendar_today

Updated On:

Products

VMware vSphere ESXi VMware vCenter Server VMware vSphere Foundation

Issue/Introduction

This article provides upgrade guidance for environments applying  (8.0 U3k) patch to address VMSA-2026-0006.1 vulnerability while planning future migrations to VMware vSphere Foundation (VVF) 9.1.x. or VMware Cloud Foundation 9.1.x

Environment

  • VMware vCenter Server 8.0 U3g

  • VMware vCenter Server 8.0 U3k

  • VMware ESXi 8.0 U3g

  • VMware vSphere Foundation (VVF) 9.1.0

  • VMware Cloud Foundation (VCF) 9.1.0

Cause

Security releases often contain updated code branches that can replace the code in major baseline releases. Upgrading a component to a newer patch release (like 8.0 U3k) can create a scenario where upgrading to an existing major release (like 9.1.0) is classified as an unsupported "back-in-time" upgrade.

Resolution

Upgrading vCenter Server to 8.0 U3k will temporarily block the upgrade path to VVF 9.1.0. If the U3k patch is applied, the environment must remain on the 8.0 U3k branch until a future VVF 9.1.x release is published that officially restores the forward upgrade path from 8.0 U3k.

From a standard VMware interoperability perspective, there are no compatibility issues between vCenter Server 8.0 U3k and ESXi 8.0 U3g. It is fully supported to manage an older ESXi 8.0 update version with a patched vCenter 8.0 instance. Check Interoperability Matrix

However, leaving ESXi hosts on 8.0 U3g leaves the infrastructure vulnerable to critical exploits such as CVE-2026-47876, an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. Without applying the corresponding ESXi 8.0 U3k patch, an attacker with local administrative privileges inside a virtual machine could potentially execute code directly on the underlying ESXi host. It is strongly advised to apply the 8.0 U3k patch to both vCenter Server and ESXi to fully secure the environment unless there's an active planned migration to VVF 9.1.X./VCF 9.1.x

Once Broadcom publishes a future VVF 9.1.x/VCF 9.1.x release that explicitly supports upgrading from 8.0 U3k, standard VVF 9.1/VCF 9.1 upgrade plans can resume.

Additional Information