We'd like to make you aware of multiple critical security vulnerabilities recently disclosed by Broadcom (VMSA-2026-0006) affecting VMware vCenter Server and VMware ESX/ESXi. Two of these carry a CVSS score of 9.8 and could allow an attacker with network access to fully compromise your vCenter, so we recommend prompt attention.
vCenter Server: 9.1.x, 9.0.x, and 8.0
ESX / ESXi: 9.1.x, 9.0.x, and 8.0
Since patches are cumulative, updating to the latest fixed build below remediates all five CVEs in one hit.
We strongly encourage reviewing your environment to identify affected versions and updating to the fixed builds below as soon as possible. As always, patch vCenter before your ESXi hosts.
vCenter 9.1.x → 9.1.0.0300
vCenter 9.0.x → 9.0.2.0100
vCenter 8.0 → 8.0 U3k
ESXi 9.1.x → ESXi 9.1.0.0200 (build 25557999)
ESXi 9.0.x → ESXi 9.0.2.0100 (build 25595025)
ESXi 8.0 → ESXi 8.0 U3k (build 25595708)
Once a vulnerability and its patch are publicly disclosed, attackers commonly attempt to reverse-engineer the fix to target unpatched deployments, so prompt patching matters here.
Please Note: If you are using 3rd party applications like Zerto Replication, then you will need to wait until these updates are supported before patching.
At Kyocera, we understand the critical importance of securing your infrastructure. If you need assistance in reviewing or resolving this issue, please don't hesitate to contact our team. You can reach our helpdesk at help@dau.kyocera.com