Full Report
VMware security advisory (AV26-763)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in VMware ESXi, vCenter, Workstation, and Fusion
## CVE Details
*Note: Based on the provided advisory, multiple CVEs are addressed in this cumulative update.*
- **CVE ID:** CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709
- **CVSS Score:** Not explicitly listed in the summary, typically ranging from High to Critical for these product suites.
- **CWE:** Varies by CVE (includes potential Use-after-free, Out-of-bounds Read/Write, or Heap Buffer Overflows common to these components).
## Affected Systems
- **Products:**
- VMware Cloud Foundation
- VMware ESXi
- VMware Fusion
- VMware Telco Cloud Infrastructure / Platform
- VMware Workstation
- VMware vCenter Server
- VMware vSphere Foundation
- **Versions:**
- Cloud Foundation: 5.x, 9.0.x.x, 9.1.x.x (Prior to 5.2.3)
- ESXi: Prior to 9.0.2.0100, 9.1.0.0, 9.1.0.0200, 80U3i, 80U3k
- Fusion: Prior to 26H1
- Workstation: Prior to 26H1
- vCenter: Prior to 8.0 U3k, 9.0.2.0100, 9.1.0.0300
- **Configurations:** Specific configurations are typically related to virtual hardware versions and administrative interface accessibility.
## Vulnerability Description
This advisory addresses a cluster of security flaws across several VMware virtualization components. These flaws generally involve:
1. **Virtual USB Controllers / AHCI Controllers:** Often linked to sandbox escapes or memory corruption.
2. **vCenter Directory Services/API:** Potential for remote code execution or privilege escalation.
3. **ESXi Hypervisor:** Flaws that could allow a guest VM to crash the host (DoS) or potentially execute code on the host.
## Exploitation
- **Status:** Not currently listed as exploited in the wild; however, VMware patches are frequent targets for reverse engineering.
- **Complexity:** Medium to High (Sandbox escapes usually require sophisticated chained exploits).
- **Attack Vector:** Network (for vCenter vulnerabilities) | Local (for ESXi/Workstation guest-to-host escapes).
## Impact
- **Confidentiality:** High (Potential access to host memory or adjacent VM data).
- **Integrity:** High (Potential for unauthorized modification of system files or VM states).
- **Availability:** High (Risk of host crashes or service downtime).
## Remediation
### Patches
Users are advised to upgrade to the following versions or higher:
- **ESXi:** 9.0.2.0100-25595025, 9.1.0.0200-25557999, or ESXi80U3k-25595708.
- **vCenter:** 8.0 U3k, 9.0.2.0100, or 9.1.0.0300.
- **Workstation/Fusion:** Version 26H1.
- **Cloud Foundation:** Version 5.2.3.
### Workarounds
- Disabling unnecessary hardware devices (e.g., USB controllers, CD-ROM drives) in VM settings.
- Restricting network access to vCenter Server management interfaces to trusted administrative subnets only.
## Detection
- **Indicators of Compromise:** Unusual service restarts (vpxd), unexpected core dumps in `/var/core/`, or unauthorized administrative logins in vCenter logs.
- **Detection methods and tools:** Utilize VMware Skyline for automated vulnerability scanning and audit logs for anomalous API calls.
## References
- **Vendor Advisory:** hxxps[://]support[.]broadcom[.]com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
- **CCCS Advisory:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/vmware-security-advisory-av26-763