Out-of-Bounds Read Vulnerability in VMware ESX, Workstation, and Fusion
CVE-2026-41703

7.6HIGH

Key Information:

Vendor

Vmware

Vendor
CVE Published:
30 July 2026

Badges

πŸ’° RansomwareπŸ‘Ύ Exploit ExistsπŸ“° News Worthy

What is CVE-2026-41703?

VMware ESX, Workstation, and Fusion are susceptible to an out-of-bounds read vulnerability. This flaw allows qualified malicious actors to exploit VM deployment privileges, potentially leading to confidential information being exposed or causing a Denial-of-Service (DoS) condition on the host process. In the context of Workstation and Fusion, the repercussions primarily include the risk of information disclosure.

Affected Version(s)

Cloud Foundation 9.1.x.x

Cloud Foundation 9.0.x.x

Cloud Foundation 5.x < 5.2.3

News Articles

VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.

2 weeks ago

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • πŸ’°

    Used in Ransomware

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

.