Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
7.6
CVE-2026-41703PATCHED
VMware · Cloud Foundation

Out-of-bounds read vulnerability

Description

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

Affected Products

VendorProductVersions
VMwareCloud Foundation9.1.x.x, 9.0.x.x, 5.x, 9.1.x.x, 9.0.x.x, 9.1.x.x, 9.0.x.x, 8.0, 25H2, 25H2, 5.1.x, 5.0.x

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
vmwareesxmitre_affected90%
vmwareworkstationmitre_affected90%
vmwarefusionmitre_affected90%
vmwaretelco cloudmitre_affected90%
vmwarevsphere foundationmitre_affected90%

References

  • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

Related News (6 articles)

Tier D
CSO Online12d ago
Broadcom patches vulnerabilities all over VMware
→ No new info (linked only)
Tier D
BleepingComputer13d ago
VMware fixes three critical flaws allowing auth bypass, VM escapes
→ No new info (linked only)
Tier B
CCCS Canada13d ago
VMware security advisory (AV26-763)
→ No new info (linked only)
Tier C
VulDB13d ago
CVE-2026-41703 | VMware ESX/Fusion/Workstation out-of-bounds
→ No new info (linked only)
Tier D
Heise Security13d ago
VMware ESX, vCenter, Workstation und Fusion: Updates schließen kritische Lücken
→ No new info (linked only)
Tier B
CERT-FR13d ago
Multiples vulnérabilités dans les produits VMware (30 juillet 2026)
→ No new info (linked only)
CVSS 3.17.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
5.2.3ESXi-9.1.0.0-25370933ESXi-9.0.2.0100-25595025ESXi80U3i-2520584526H1
CWECWE-125
PublishedJul 30, 2026
Last enriched13d ago
Trending Score14
Source articles6
Independent6
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59310EXPKEV
vCenter directory-traversal vulnerability
Trending: 137
CRITICALCVE-2026-59309
vCenter authentication-bypass vulnerability
Trending: 16
CRITICALCVE-2026-47876
VMXNET3 out-of-bounds write vulnerability
Trending: 14
HIGHCVE-2026-41842
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Trending: 13
HIGHCVE-2026-41850EXP
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Trending: 11

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 30, 2026
Discovered by ZDM
Jul 30, 2026
Patch Available
Jul 30, 2026