Login
← All news

VMSA-2026-0006: Urgent patch for VMware vCenter and ESX

Broadcom has released critical updates for vCenter, ESX, and other VMware products after discovering five vulnerabilities, two of which can be exploited without authentication.

Based on reporting by DNSC

Broadcom released security bulletin VMSA-2026-0006 on July 29, 2026, which fixes five vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion. The DNSC issued a separate alert about this bulletin, recommending that the available patches be applied immediately.

What vulnerabilities have been discovered

The two most serious issues affect VMware vCenter Server and received the maximum severity score, 9.8 out of 10 on the CVSSv3 scale.

Which products are affected

The bulletin covers VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, as well as the larger components that include: VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. All versions prior to those marked as fixed in the official bulletin are vulnerable.

Patched versions available

Broadcom has already released updates for all affected product lines.

  • vCenter Server 8.0 is fixed with version 8.0 Update 3k.
  • For vCenter 9.0, the patch is version 9.0.2.0100, and for line 9.1, version 9.1.0.0300.
  • ESX 8.0 gets fix through ESXi80U3k-25595708, and for lines 9.0 and 9.1 there are dedicated updates.
  • Cloud Foundation 5.x releases benefit from asynchronous fixing, separate from patches of individual components.

Broadcom specifies that patches are cumulative, so the latest version also includes previous fixes.

There are no workarounds

For the two critical vulnerabilities in vCenter there is no workaround. The only effective measure is to apply the updates published by Broadcom. At the moment, no active exploitation of these vulnerabilities has been reported in the real environment.

What System Administrators Need to Do

If you are administering VMware infrastructure, immediately check the installed version of vCenter and ESX and compare it to the repaired versions in VMSA-2026-0006. In addition to patching, consider additional protective measures.

  • Restrict access to management interfaces through network segmentation and firewall rules.
  • Enable multi-factor authentication for administrative accounts.
  • Check your system logs for signs of unauthorized access or suspicious activity prior to patching.

If you manage virtualized infrastructure for customers or for your organization, treat this bulletin as an immediate priority, especially for vCenter servers exposed on the network.