Skip to content
VMwareCVE-2026-41703

VMware Cloud Foundation: out-of-bounds read

High7.6CVE-2026-41703 · Published Jul 30, 2026

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

VMware advisory

Affected versions

PackageAffectedFixed in
Cloud Foundation
Product
<= 9.1.x.xNo fix yet
<= 9.0.x.xNo fix yet
>= 5.x, < 5.2.35.2.3
ESX
Product
>= 9.1.x.x, < ESXi-9.1.0.0-25370933ESXi-9.1.0.0-25370933
>= 9.0.x.x, < ESXi-9.0.2.0100-25595025ESXi-9.0.2.0100-25595025
>= 8.0, < ESXi80U3i-25205845ESXi80U3i-25205845
Fusion
Product
>= 25H2, < 26H126H1
Telco Cloud Platform
Product
<= 5.1.xNo fix yet
<= 5.0.xNo fix yet
Workstation
Product
>= 25H2, < 26H126H1
vSphere Foundation
Product
<= 9.1.x.xNo fix yet
<= 9.0.x.xNo fix yet
Details and references

More VMware advisories

All VMware
Advisory
VMware ESX contains an insufficient logging vulnerability
Low2.7Jul 30
VMware Cloud Foundation: authentication bypass
Critical9.8Jul 30
VMware Cloud Foundation: path traversal
Critical9.8Jul 30
VMware Cloud Foundation: out-of-bounds write
Critical9.3Jul 30
VMware Spring Tools for: secrets in logs
Low3.3Jul 30
VMware Spring Tools for Eclipse: cleartext storage
Medium4.4Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.