CVE-2026-41703
VMware · Cloud Foundation, ESX, Workstation, Fusion
VMware products, including Cloud Foundation, ESX, Workstation, and Fusion, are affected by an out-of-bounds read vulnerability that could be exploited by an authenticated user.
Executive summary
Critical virtualization products from VMware are susceptible to an out-of-bounds read vulnerability that could be leveraged by attackers with high privileges to impact system stability.
Vulnerability
This is an out-of-bounds read vulnerability (CWE-125). It requires an attacker to possess high privileges to successfully exploit the flaw, potentially resulting in unauthorized information disclosure or system instability.
Business impact
The CVSS score of 7.6 indicates a high-severity threat to business operations. Exploitation could allow an attacker to read sensitive memory contents or cause a denial of service, potentially impacting the integrity and availability of virtualized workloads across the enterprise.
Remediation
Immediate Action: Apply the specific security patches provided by Broadcom/VMware for your respective product version as listed in the official security advisory.
Proactive Monitoring: Monitor virtual machine and hypervisor logs for unexpected crashes or error messages related to memory access violations.
Compensating Controls: Restrict administrative access to the hypervisor management interface to a limited set of trusted personnel and secure management networks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the broad impact across VMware's product portfolio, administrators should consult the Broadcom support portal to identify and apply the correct patches for their environment. Immediate remediation is necessary to prevent potential exploitation of the hypervisor layer.