Skip to content
VMwareCVE-2026-41709

VMware ESX contains an insufficient logging vulnerability

Low2.7CVE-2026-41709 · Published Jul 30, 2026

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

VMware advisory

Affected versions

PackageAffectedFixed in
Cloud Foundation
Product
<= 9.1.x.xNo fix yet
<= 9.0.x.xNo fix yet
>= 5.x, < 5.2.45.2.4
ESX
Product
>= 9.1.x.x, < ESXi-9.1.0.0-25370933ESXi-9.1.0.0-25370933
>= 9.0.x.x, < ESXi-9.0.2.0100-25595025ESXi-9.0.2.0100-25595025
>= 8.0, < ESXi80U3j-25429389ESXi80U3j-25429389
Telco Cloud Platform
Product
<= 5.1.xNo fix yet
<= 5.0.xNo fix yet
vSphere Foundation
Product
<= 9.1.x.xNo fix yet
<= 9.0.x.xNo fix yet
Details and references

More VMware advisories

All VMware
Advisory
VMware Cloud Foundation: authentication bypass
Critical9.8Jul 30
VMware Cloud Foundation: path traversal
Critical9.8Jul 30
VMware Cloud Foundation: out-of-bounds write
Critical9.3Jul 30
VMware Cloud Foundation: out-of-bounds read
High7.6Jul 30
VMware Spring Tools for: secrets in logs
Low3.3Jul 30
VMware Spring Tools for Eclipse: cleartext storage
Medium4.4Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.