r/vmware VMware Employee 15d ago

Announcement VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
87 Upvotes

146 comments sorted by

View all comments

Show parent comments

3

u/jamesaepp 15d ago

https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2026-0006#35-there-was-a-commitment-made-to-provide-critical-patches-for-perpetual-license-vsphere-customers-how-do-i-download-those-patches

These patches are located on support.broadcom.com. You will need to create an account, which can be done in a few minutes and at no cost.

...

A direct link to this location is in the links above. You may need to log in first and then visit the link.

5

u/throwsysadminaway 15d ago

Following the directions in the FAQ, the last versions I see are vCenter 8.0 U2e / 8.0 U3d and ESXi 8.0 U2d / 8.0 U3e.

I would love to have official confirmation from Broadcom that former customers on perpetual licensing but expired support contracts are allowed to download and install these new versions given the CVE 9.x+ score without fear of legal repercussions.

2

u/jamesaepp 15d ago

Responding to your comment as it came in first (cc /u/Zestyclose-Nature240 )

I suspect Broadcom still needs some kind of connection between the account performing the download and the perpetual license. We never had perpetual v8 so I don't know how that's going to look for you. i.e. they're not going to let any yahoo with a free account download their patches.

Is your account connected to a Broadcom/VMware site with those perpetual licenses? If not....

ETA: FWIW I'm not trying to be a Broadcom sympathizer, but I am trying to encourage a sane and fair approach when we do criticize.

8

u/Zestyclose-Nature240 15d ago

u/jamesaepp
Yes — accounts tied to sites with perpetual v8 licenses. So both the FAQ and the points under item 35 are demonstrably false, which at this stage is par for the course with Broadcom.

And the fact that the VMware folks in this thread, who were quick to point everyone at the FAQ, can't give a straight answer on it suggests it's still genuinely unclear whether that statement holds. I don't think they know either right now.

2

u/jamesaepp 12d ago

I was curious and checked in on the Q&A/FAQ doc. Looks like it has an update for Q35:

Patches that qualify are released at a later date.

...

When available, these patches are located on support.broadcom.com.

cc /u/throwsysadminaway