Cyber Resilience
← All news
Confirmed

VMware Products: CVSS (Max): 9.3

Our takeBroadcom's latest VMware advisory tops out at CVSS 9.3. If you run VMware — ESXi, vSphere or the rest — schedule this update: a hypervisor compromise reaches every VM on the host, which is why ransomware crews keep targeting it. Same advice whatever your size.
Sources (1)
What this means for you — Security leader:Patch affected VMware products (vCenter, ESXi, Workstation, Fusion and others) to the versions listed in the ESB-2026.10581 advisory. CVSS 9.3 flaws are confirmed exploitable; prioritize based on your exposure.
What this means for you — Lean IT orgs:If you run any VMware software (vCenter, ESXi, Workstation or Fusion), apply the updates in the advisory immediately. Most cloud-hosted setups are unaffected.
What this means for you — MSP:Review every client running on-premises VMware products and schedule patching for the CVSS 9.3 issues listed in ESB-2026.10581. Confirm which clients are on affected versions and which use cloud or third-party alternatives.
What this means for you — Researcher:Review the full technical details and exploit vectors once VMware publishes the linked advisories.