VMware security advisory (AV26-763)
Serial number: AV26-763 Date: July 30, 2026 As of July 30, 2026, VMware is affected by vulnerabilities in the following products: Cloud Foundation 5.x 9.0.x.x 9.1.x.x Prior to 5.2.3 ESX Prior to ESXi-9.0.2.0100-25595025 Prior to ESXi-9.1.0.0-25370933 Prior to ESXi-9.1.0.0200-25557999 Prior to ESXi80U3i-25205845 Prior to ESXi80U3k-25595708 Fusion Prior to 26H1 Telco Cloud Infrastructure 3.0 Telco Cloud Platform 4.x 5.0.x 5.1.x Workstation Prior to 26H1 vCenter Prior to 8.0 U3k Prior to 9.0.2.0100 Prior to 9.1.0.0300 vSphere Foundation 9.0.x.x 9.1.x.x The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) Security Advisories - VMware Cloud Foundation
CSIRTS triage
- What
- VMware products are affected by multiple vulnerabilities.
- Who is affected
- Users and administrators of various VMware products listed in the advisory.
- Urgency
- Remediation is necessary due to multiple vulnerabilities, though severity is unknown.
- Action
- Review the provided web links and apply necessary updates as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/vmware-security-advisory-av26-763
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-593090.74% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all scored CVEs.
- Moderate exploitation riskCVE-2026-593101.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all scored CVEs.
- Low exploitation riskCVE-2026-478760.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
- Low exploitation riskCVE-2026-417030.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-417090.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59309 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59310 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47876 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41703 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41709 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] VMware Products: Multiple vulnerabilitiescert-bund
- lowCVE-2026-41709: VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exp…nvd
- criticalCVE-2026-59310: VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious …nvd
- criticalCVE-2026-59309: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service…nvd
- criticalCVE-2026-47876: VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapte…nvd
- highCVE-2026-41703: VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious a…nvd
- unknownMultiple Vulnerabilities in VMware Products (July 30, 2026)cert-fr-avis
- unknownNCSC-2026-0269 [1.01] [M/H] Vulnerabilities fixed in VMware productsncsc-nl
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30