Executive brief
VMware virtualization products (ESXi, Workstation, and Fusion) contain a security flaw that can be triggered by users with permissions to deploy virtual machines. On enterprise ESXi systems, an attacker could crash the host server or access sensitive information. On personal Workstation and Fusion software, the risk is limited to the unauthorized disclosure of information.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in VMware ESXi, Workstation, and Fusion. A malicious actor with VM deployment privileges can exploit this flaw via the network to trigger an out-of-bounds memory access. On ESXi, this can result in a Denial-of-Service (DoS) of the host process or information disclosure. On Workstation and Fusion, the impact is limited to information disclosure. Patches are available for affected versions, including ESXi 8.0, 9.0, and 9.1, and Workstation/Fusion version 26H1.
Affected products
- VMware ESXi 9.1.x.x before ESXi-9.1.0.0-25370933, 9.0.x.x before ESXi-9.0.2.0100-25595025, 8.0 before ESXi80U3i-25205845
- VMware Workstation 25H2 before 26H1
- VMware Fusion 25H2 before 26H1
- VMware Cloud Foundation 5.x before 5.2.3, 9.0.x.x, 9.1.x.x
- VMware Telco Cloud Platform 5.0.x, 5.1.x
Timeline
- 2026-07-29: advisory: Initial publication by Broadcom (VMSA-2026-0006)
- 2026-07-30: disclosed: NVD publication date