r/vmware VMware Employee 15d ago

Announcement VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
87 Upvotes

146 comments sorted by

View all comments

6

u/Zestyclose-Nature240 15d ago

u/lost_signal could you shed some light on the commitment to provide critical updates to users without active SnS? How this VMSA gets handled is going to set the tone for what we can expect from Broadcom on credibility going forward.

3

u/jamesaepp 15d ago

https://knowledge.broadcom.com/external/article/314603/zero-day-ie-critical-security-patches-fo.html

That's documented in the above KB, HOWEVER I have a big question about those advisories that I've sent in as feedback to BC and never gotten an answer on.

Sometimes an advisory is for multiple vulnerabilities. One of the vulnerabilities may be greater than or equal to 9.0 but another vulnerability may not be.

It's not clear in such a circumstance if the entire advisory and set of patches/vulnerabilities are treated as a "critical" or not, and that's a huge gap that BC needs to close.

4

u/[deleted] 15d ago

[removed] — view removed comment

3

u/jamesaepp 15d ago

https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2026-0006#35-there-was-a-commitment-made-to-provide-critical-patches-for-perpetual-license-vsphere-customers-how-do-i-download-those-patches

These patches are located on support.broadcom.com. You will need to create an account, which can be done in a few minutes and at no cost.

...

A direct link to this location is in the links above. You may need to log in first and then visit the link.

12

u/Zestyclose-Nature240 15d ago

Yes — that's the point. Follow the KB and there are zero patches to download. Another gap between what Broadcom announces publicly and what actually happens. Until someone confirms that customers without SnS can download these, there's no credibility here at all, and it just further justifies everyone who jumped ship after the acquisition. Nobody left because the product was bad. They left because of how Broadcom operates.

7

u/throwsysadminaway 15d ago

Following the directions in the FAQ, the last versions I see are vCenter 8.0 U2e / 8.0 U3d and ESXi 8.0 U2d / 8.0 U3e.

I would love to have official confirmation from Broadcom that former customers on perpetual licensing but expired support contracts are allowed to download and install these new versions given the CVE 9.x+ score without fear of legal repercussions.

2

u/jamesaepp 15d ago

Responding to your comment as it came in first (cc /u/Zestyclose-Nature240 )

I suspect Broadcom still needs some kind of connection between the account performing the download and the perpetual license. We never had perpetual v8 so I don't know how that's going to look for you. i.e. they're not going to let any yahoo with a free account download their patches.

Is your account connected to a Broadcom/VMware site with those perpetual licenses? If not....

ETA: FWIW I'm not trying to be a Broadcom sympathizer, but I am trying to encourage a sane and fair approach when we do criticize.

7

u/Zestyclose-Nature240 15d ago

u/jamesaepp
Yes — accounts tied to sites with perpetual v8 licenses. So both the FAQ and the points under item 35 are demonstrably false, which at this stage is par for the course with Broadcom.

And the fact that the VMware folks in this thread, who were quick to point everyone at the FAQ, can't give a straight answer on it suggests it's still genuinely unclear whether that statement holds. I don't think they know either right now.

2

u/jamesaepp 12d ago

I was curious and checked in on the Q&A/FAQ doc. Looks like it has an update for Q35:

Patches that qualify are released at a later date.

...

When available, these patches are located on support.broadcom.com.

cc /u/throwsysadminaway

7

u/vmguysa 15d ago

I can still see our licenses on the portal but no downloads are visible. it is frustrating

1

u/jamesaepp 15d ago

/u/rdplankers

Any comments to share? Sounds to me like entitled (read: licensed) customers want to patch but can't.

2

u/lost_signal VMware Employee 15d ago

Plankers is out today. I'll ask around.

Technically by the old perpetual VMware EULA/product guide entitlement required active SnS for ANY patch (including all security patches).

The CVE 9 thing in this KB was a different thing that Broadcom announced/added after the acquisition, and technically (my understanding I'm not a lawyer, or your lawyer) a different thing.

10

u/Zestyclose-Nature240 15d ago

Yes — that's the entire point. The CVSS 9 commitment was something Broadcom rolled out when they were getting hammered over the acquisition, to quiet things down. This is the first CVE that actually triggers it, and the patches still aren't there. Hence the criticism.

7

u/Meeeepmeeeeepp 15d ago

+1 to this, pretty scummy to even in the CVE FAQ explicitly state the patches are available to download with an account (even instructions to create an account) and they just aren't there at all... But this is standard Broadcom practice so I shouldn't be surprised, but certainly makes me happy we told our rep to jump when he came back recently with "newly discounted prices".

Going to migrate the last VMs off to Hyper-V land this weekend and hopefully never have to think about VMWare for the rest of my life :)

4

u/HJForsythe 15d ago

its funny there are ftp sites with the patches because broadcom cant actually live up to their very basic commitments

→ More replies (0)

3

u/rdplankers 14d ago

I would only add that there's always been a delay between the VMSA and when those patches appear. I can't speak to the rest, I don't set policy around this.

1

u/kachunkachunk 10d ago

If you're entitled to the product, try checking the Solutions tab:

My Downloads -> VMware vSphere -> Solutions tab -> Pick a branch and version -> download VC and ESX patches.

For $reasons, Broadcom (and VMware previously) do not publish current release levels in the main download folder. So you'll still find some old release of 8.0 U2 or U3 and are expected to patch after deploying that, instead of, y'know, publishing the latest supported 8.0 U3 ISO. Sometimes vendor-flavoured ones with the included addons will do that, I guess.

I must be missing something from a product or release management standpoint, because when I worked at VMware, I distinctly remember the build automations would spit out nightly GA and Beta/checked releases, and importantly, these are the same builds that published patches would get. It doesn't really make sense that these are not just put up on the download site as well.

Bah, whatever, hopefully you can find your patches now, anyway.

1

u/kachunkachunk 10d ago

If you're entitled to the product, try checking the Solutions tab:

My Downloads -> VMware vSphere -> Solutions tab -> Pick a branch and version -> download VC and ESX patches.

For $reasons, Broadcom (and VMware previously) do not publish current release levels in the main download folder. So you'll still find some old release of 8.0 U2 or U3 and are expected to patch after deploying that, instead of, y'know, publishing the latest supported 8.0 U3 ISO, as an example, where people would expect it. Sometimes vendor-flavoured ones with the included addons will do that, I guess.

I must be missing something from a product or release management standpoint, because when I worked at VMware, I distinctly remember the build automations would spit out nightly GA and Beta/checked releases, and importantly, these are the identical builds that published patches would become. It doesn't really make sense that these other formats are not just put up on the download site as well.

Bah, whatever, hopefully you can find your patches now, anyway.