CVE-2026-41703
Serial number: AV26-763 Date: July 30, 2026 As of July 30, 2026, VMware is affected by vulnerabilities in the following products: Cloud Foundation 5.x 9.0.x.x 9.1.x.x Prior to 5.2.3 ESX Prior to ESXi-9.0.2.0100-25595025 Prior to ESXi-9.1.0.0-25370933 Prior to ESXi-9.1.0.0200-25557999 Prior to ESXi80U3i-25205845 Prior to ESXi80U3k-25595708 Fusion Prior to 26H1 Telco Cloud Infrastructure 3.0 Telco Cloud Platform 4.x 5.0.x 5.1.x Workstation Prior to 26H1 vCenter Prior to 8.0 U3k Prior to 9.0.2.0100 Prior to 9.1.0.0300 vSphere Foundation 9.0.x.x 9.1.x.x The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) Security Advisories - VMware Cloud Foundation
CSIRTS triage
- What
- VMware products are affected by multiple vulnerabilities.
- Who is affected
- Users and administrators of various VMware products listed in the advisory.
- Urgency
- Remediation is necessary due to multiple vulnerabilities, though severity is unknown.
- Action
- Review the provided web links and apply necessary updates as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-41703
Get an email if CVE-2026-41703 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
Advisory coverage (5)
- high[NEW] [high] VMware Products: Multiple vulnerabilitiescert-bund · 2026-07-31
- unknownVMware security advisory (AV26-763)cccs · 2026-07-30
- highCVE-2026-41703: VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious a…nvd · 2026-07-30
- unknownMultiple Vulnerabilities in VMware Products (July 30, 2026)cert-fr-avis · 2026-07-30
- unknownNCSC-2026-0269 [1.01] [M/H] Vulnerabilities fixed in VMware productsncsc-nl · 2026-07-29
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-41703)