Cyber Resilience
← All news

VMware security advisory (AV26-763)

Our takeCCCS flags VMware Cloud Foundation and ESXi flaws. Patch if you run these yourself (enterprises, MSPs); most smaller shops don't host vSphere and can ignore this one.
Sources (1)
What this means for you — Security leader:Apply the VMware patches for Cloud Foundation 5.2.3+, ESXi 9.0.2 build 25595025, ESXi 9.1 builds 25370933/25557999, and the listed ESXi 8.0 U3 updates. Prioritize internet-facing ESXi hosts and vSphere management layers.
What this means for you — Lean IT orgs:If you run VMware ESXi or Cloud Foundation, check your version numbers today and apply the fixes VMware released on July 30. Most lean-IT teams should ask their hosting provider or MSP to confirm the update is done.
What this means for you — MSP:Patch all managed VMware ESXi hosts (9.0.2-25595025, 9.1.0-25370933/25557999, 8.0U3i-25205845, 8.0U3k-25595708) and Cloud Foundation instances (5.2.3+) immediately. Scan client estates for exposure.
What this means for you — Researcher:VMware advisory AV26-763 discloses vulnerabilities in Cloud Foundation 5.x and multiple ESXi releases; full details and patches are in the CCCS-linked advisory.