{"id":70443,"date":"2026-08-03T09:00:05","date_gmt":"2026-08-03T07:00:05","guid":{"rendered":"https:\/\/nolabnoparty.com\/?p=70443"},"modified":"2026-07-31T16:18:48","modified_gmt":"2026-07-31T14:18:48","slug":"vmware-security-advisory-vmsa-2026-0006","status":"publish","type":"post","link":"https:\/\/nolabnoparty.com\/en\/vmware-security-advisory-vmsa-2026-0006\/","title":{"rendered":"VMware security advisory\u00a0VMSA-2026-0006"},"content":{"rendered":"<p><img decoding=\"async\" class=\"aligncenter wp-image-70444 size-full\" title=\"vmware-security-advisory-vmsa-2026-0006-01\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/07\/vmware-security-advisory-vmsa-2026-0006-01.jpg\" alt=\"vmware-security-advisory-vmsa-2026-0006-01\" width=\"602\" height=\"202\" \/><\/p>\n<p>Broadcom published VMware security advisory <a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/38017\" target=\"_blank\" rel=\"noopener\" data-gtm-location=\"content-rte-link\" data-gtm-cta=\"vmsa-2026-0006\">VMSA-2026-0006<\/a> addressing multiple vulnerabilities across <strong>several VMware products<\/strong>.<\/p>\n<p data-path-to-node=\"3\">The reported vulnerabilities impact the following platforms:<!--more--><\/p>\n<ul>\n<li data-path-to-node=\"4,0,0\">VMware ESXi, vCenter Server, Workstation, and Fusion<\/li>\n<li data-path-to-node=\"4,0,0\">VMware Cloud Foundation and vSphere Foundation<\/li>\n<li data-path-to-node=\"4,0,0\">Telco Cloud Platform and Telco Cloud Infrastructure<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70447\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/07\/vmware-security-advisory-vmsa-2026-0006-02-600x195.jpg\" alt=\"\" width=\"600\" height=\"195\" title=\"\"><\/p>\n<p>Most notably, there are <strong>two critical vulnerabilities<\/strong> affecting vCenter Server, both carrying a <strong>CVSSv3.1 score of 9.8<\/strong>:<\/p>\n<ul>\n<li><strong>CVE-2026-59309<\/strong> - Allows a malicious actor with network access to bypass authentication and gain unauthorized access to the system.<\/li>\n<li><strong>CVE-2026-59310<\/strong> - Allows a malicious actor with network access to execute arbitrary code.<\/li>\n<\/ul>\n<p>Broadcom has already <strong>released patches to mitigate<\/strong> these issues. Organizations using vCenter Server should apply these updates as soon as possible to <strong>prevent potential exploitation<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70448\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/07\/vmware-security-advisory-vmsa-2026-0006-03-600x304.jpg\" alt=\"\" width=\"600\" height=\"304\" title=\"\"><\/p>\n<p>&nbsp;<\/p>\n<h2>Remediation and mitigation of VMSA-2026-0006<\/h2>\n<p>Alongside the vCenter patches, Broadcom addressed three additional vulnerabilities:<\/p>\n<ul>\n<li><strong>CVE-2026-47876<\/strong> (score CVSS: 9.3) - An out-of-bounds write flaw in the VMXNET3 virtual network adapter allows a malicious actor with local admin privileges on a VM to execute arbitrary code on the underlying host.<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70451\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/07\/vmware-security-advisory-vmsa-2026-0006-04-600x398.jpg\" alt=\"\" width=\"600\" height=\"398\" title=\"\"><\/p>\n<ul>\n<li><strong>CVE-2026-41703<\/strong> (score CVSS: 7.6) - An out-of-bounds read vulnerability triggered during VM deployment. On ESXi, it can lead to information disclosure or a Denial-of-Service (DoS) condition. On Workstation and Fusion, the impact is strictly limited to information disclosure.<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70452\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/07\/vmware-security-advisory-vmsa-2026-0006-05-600x358.jpg\" alt=\"\" width=\"600\" height=\"358\" title=\"\"><\/p>\n<ul>\n<li><strong>CVE-2026-41709<\/strong> (score CVSS: 2.7) - An insufficient logging flaw allows a malicious administrator to perform specific unauthorized operations without generating log entries.<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70453\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/07\/vmware-security-advisory-vmsa-2026-0006-06-600x401.jpg\" alt=\"\" width=\"600\" height=\"401\" title=\"\"><\/p>\n<p>Because these are critical security patches, it is strongly recommended to apply them as soon as possible to <strong>mitigate potential risks<\/strong>.<\/p>\n<p><img decoding=\"async\" title=\"signature\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/images\/firma.jpg\" alt=\"signature\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Broadcom published VMware security advisory VMSA-2026-0006 addressing multiple vulnerabilities across several VMware products. The reported vulnerabilities impact the following platforms:<\/p>\n","protected":false},"author":3,"featured_media":70444,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"no","rop_publish_now_accounts":{"facebook_2879994398731222_17841400390232720":"","mastodon_115463926174894442_115463926174894442":"","linkedin_93tdZWzMZc_93tdZWzMZc":"","bluesky_did:plc:tkabz5kl2rukzdwtuongv3kz_did:plc:tkabz5kl2rukzdwtuongv3kz":""},"rop_publish_now_history":[{"account":"facebook_2879994398731222_17841400390232720","service":"facebook","timestamp":1785740448,"status":"queued"},{"account":"linkedin_93tdZWzMZc_93tdZWzMZc","service":"linkedin","timestamp":1787317976,"status":"success"},{"account":"mastodon_115463926174894442_115463926174894442","service":"mastodon","timestamp":1787318004,"status":"success"},{"account":"mastodon_116849603311017847_116849603311017847","service":"mastodon","timestamp":1787318019,"status":"success"},{"account":"twitter_113568041_113568041","service":"twitter","timestamp":1787317990,"status":"error"}],"rop_publish_now_status":"queued","footnotes":""},"categories":[903,2701],"tags":[580,2974,583,3130],"class_list":["post-70443","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vmware-en","category-vsphere-en","tag-esxi-en","tag-security-advisory","tag-vcenter-en","tag-vmsa-2026-0006","has_thumb"],"_links":{"self":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/70443","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/comments?post=70443"}],"version-history":[{"count":4,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/70443\/revisions"}],"predecessor-version":[{"id":70466,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/70443\/revisions\/70466"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media\/70444"}],"wp:attachment":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media?parent=70443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/categories?post=70443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/tags?post=70443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}