<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1741336722824154&amp;ev=PageView&amp;noscript=1">
Skip to the main content.

Print Solutions

Benefit from smart ideas, lower costs, greater productivity. Choose from award-winning printers, software solutions and consumables

Insights

We combine professional expertise with a human kind of partnership

Support Centre

Get the right help and advice, register a product and see why our commitment to you matters.

Kyocera_lead_Huon_IT_co branding_RGB

Australian Unity: Critical Security Advisory – VMware Vulnerability (VMSA-2026-0006)

Australian Unity: Critical Security Advisory – VMware Vulnerability (VMSA-2026-0006)

We'd like to make you aware of multiple critical security vulnerabilities recently disclosed by Broadcom (VMSA-2026-0006) affecting VMware vCenter Server and VMware ESX/ESXi. Two of these carry a CVSS score of 9.8 and could allow an attacker with network access to fully compromise your vCenter, so we recommend prompt attention.

Summary of the Vulnerabilities:
  • CVE-2026-59309 (CVSS 9.8, Critical) – An authentication bypass in the vCenter Directory Service. An attacker with network access to vCenter can bypass authentication and gain unauthorised access.
  • CVE-2026-59310 (CVSS 9.8, Critical) – A directory traversal flaw in the vCenter Syslog service, allowing an attacker with network access to vCenter to execute arbitrary code.
  • CVE-2026-47876 (CVSS 9.3, Critical) – An out-of-bounds write in the ESX VMXNET3 virtual network adapter. An attacker with local admin rights on a guest VM (using a VMXNET3 adapter) could execute code on the host — i.e. a VM escape. VMs using non-VMXNET3 adapters are not affected.
  • CVE-2026-41703 (CVSS 7.6, Important) – An out-of-bounds read in ESX that could lead to information disclosure or a denial-of-service condition on the host process.
  • CVE-2026-41709 (CVSS 2.7, Low) – Insufficient logging in ESX that could allow a malicious administrator to perform actions without them being logged.
  • Important: There are no workarounds for any of these — patching is the only remediation.
  • Full Broadcom advisory can be found here.
What's Affected:

vCenter Server: 9.1.x, 9.0.x, and 8.0
ESX / ESXi: 9.1.x, 9.0.x, and 8.0
Since patches are cumulative, updating to the latest fixed build below remediates all five CVEs in one hit.

Recommended Action:

We strongly encourage reviewing your environment to identify affected versions and updating to the fixed builds below as soon as possible. As always, patch vCenter before your ESXi hosts.

  • vCenter 9.1.x 9.1.0.0300

  • vCenter 9.0.x 9.0.2.0100

  • vCenter 8.0 8.0 U3k

  • ESXi 9.1.x ESXi 9.1.0.0200 (build 25557999)

  • ESXi 9.0.x ESXi 9.0.2.0100 (build 25595025)

  • ESXi 8.0 ESXi 8.0 U3k (build 25595708)

Once a vulnerability and its patch are publicly disclosed, attackers commonly attempt to reverse-engineer the fix to target unpatched deployments, so prompt patching matters here.

Please Note: If you are using 3rd party applications like Zerto Replication, then you will need to wait until these updates are supported before patching.

 

At Kyocera, we understand the critical importance of securing your infrastructure. If you need assistance in reviewing or resolving this issue, please don't hesitate to contact our team. You can reach our helpdesk at help@dau.kyocera.com


 

 

Important: Fortinet Vulnerabilities Affecting FortiOS Devices

Important: Fortinet Vulnerabilities Affecting FortiOS Devices

As of January 28 2026, Fortinet's Product Security Incident Response Team (PSIRT) has released several advisories addressing vulnerabilities in...

Read More
High VMware ESXi and Vcenter updates to address multiple security vulnerabilities

1 min read

High VMware ESXi and Vcenter updates to address multiple security vulnerabilities

VMware has released an update to patch multiple security vulnerabilities for their products VMware ESXi, vCenter Server, Workstation, and Fusion....

Read More
Critical VMware ESXi and Vmware Tools updates to address multiple security vulnerabilities

Critical VMware ESXi and Vmware Tools updates to address multiple security vulnerabilities

Broadcom (VMware) has published an update on multiple security vulnerabilities for their products VMware ESXi and VMware Tools.

Read More